6.5
CVSSv3

CVE-2017-12953

Published: 28/08/2017 Updated: 06/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote malicious users to cause a denial of service (invalid memory write and application crash) via a crafted gig file.

Vulnerable Product Search on Vulmon Subscribe to Product

libgig0 libgig 4.0.0

Vendor Advisories

Debian Bug report logs - #873718 libgig: CVE-2017-12950 CVE-2017-12952 CVE-2017-12953 Package: src:libgig; Maintainer for src:libgig is Debian Multimedia Maintainers <pkg-multimedia-maintainers@listsaliothdebianorg>; Reported by: Raphael Hertzog <hertzog@debianorg> Date: Wed, 30 Aug 2017 12:51:01 UTC Severity: gr ...
Debian Bug report logs - #877651 libgig: CVE-2017-12951 Package: src:libgig; Maintainer for src:libgig is Debian Multimedia Maintainers <pkg-multimedia-maintainers@listsaliothdebianorg>; Reported by: Raphael Hertzog <hertzog@debianorg> Date: Wed, 30 Aug 2017 12:51:01 UTC Severity: grave Tags: security, upstream ...
Debian Bug report logs - #877652 libgig: CVE-2017-12954 Package: src:libgig; Maintainer for src:libgig is Debian Multimedia Maintainers <pkg-multimedia-maintainers@listsaliothdebianorg>; Reported by: Raphael Hertzog <hertzog@debianorg> Date: Wed, 30 Aug 2017 12:51:01 UTC Severity: grave Tags: security, upstream ...

Exploits

================ Author : qflbwu =============== Introduction: ============= wwwlinuxsamplerorg/libgig/ libgig is a C++ library for loading, modifying existing and creating new Gigasampler (gig) files and DLS (Downloadable Sounds) Level 1/2 files, KORG sample based instruments (KSF and KMP files), SoundFont v2 (sf2) files and AKAI ...