605
VMScore

CVE-2017-6827

Published: 15/03/2017 Updated: 04/11/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote malicious users to have unspecified impact via a crafted audio file.

Vulnerable Product Search on Vulmon Subscribe to Product

audiofile audiofile 0.3.6

Vendor Advisories

Debian Bug report logs - #857651 Multiple security issues Package: src:audiofile; Maintainer for src:audiofile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 13 Mar 2017 19:03:02 UTC Severity: grave Tags: security Found in version au ...
audiofile could be made to crash or run programs if it opened a specially crafted file ...
Several vulnerabilities have been discovered in the audiofile library, which may result in denial of service or the execution of arbitrary code if a malformed audio file is processed For the stable distribution (jessie), these problems have been fixed in version 036-2+deb8u2 For the upcoming stable distribution (stretch), these problems have be ...
Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCMcpp in audiofile (aka libaudiofile and Audio File Library) 036 allows remote attackers to have unspecified impact via a crafted audio file ...
Heap-based buffer overflow in msdapcmInitializeCoefficients (msadcpcmcpp) could lead to arbitrary code execution ...