4.3
CVSSv2

CVE-2017-16942

Published: 25/11/2017 Updated: 10/06/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

It exists that libsndfile incorrectly handled certain malformed files. A remote attacker could use this issue to cause libsndfile to crash, resulting in a denial of service, or possibly execute arbitrary code.

Vulnerable Product Search on Vulmon Subscribe to Product

libsndfile project libsndfile 1.0.25

Vendor Advisories

Several security issues were fixed in libsndfile ...
In libsndfile 1025 (fixed in 1026), a divide-by-zero error exists in the function wav_w64_read_fmt_chunk() in wav_w64c, which may lead to DoS when playing a crafted audio file ...