6.8
CVSSv2

CVE-2015-7747

Published: 19/02/2020 Updated: 13/04/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote malicious users to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 15.04

canonical ubuntu linux 15.10

fedoraproject fedora 23

audio file library project audio file library

Vendor Advisories

Debian Bug report logs - #801102 audiofile: CVE-2015-7747 Package: audiofile; Maintainer for audiofile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 6 Oct 2015 10:33:02 UTC Severity: important Tags: security Found in version 036- ...
audiofile could be made to crash or run programs as your login if it opened a specially crafted file ...