4.3
CVSSv2

CVE-2017-6836

Published: 20/03/2017 Updated: 01/02/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote malicious users to cause a denial of service (crash) via a crafted file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

audiofile audiofile 0.3.6

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #857651 Multiple security issues Package: src:audiofile; Maintainer for src:audiofile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 13 Mar 2017 19:03:02 UTC Severity: grave Tags: security Found in version au ...
audiofile could be made to crash or run programs if it opened a specially crafted file ...
Several vulnerabilities have been discovered in the audiofile library, which may result in denial of service or the execution of arbitrary code if a malformed audio file is processed For the stable distribution (jessie), these problems have been fixed in version 036-2+deb8u2 For the upcoming stable distribution (stretch), these problems have be ...
Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModuleh in Audio File Library (aka audiofile) 036 allows remote attackers to cause a denial of service (crash) via a crafted file ...
audiofile: heap-based buffer overflow in Expand3To4Module::run (SimpleModuleh) ...