4.3
CVSSv2

CVE-2017-7741

Published: 12/04/2017 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In libsndfile prior to 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libsndfile project libsndfile

Vendor Advisories

Several security issues were fixed in libsndfile ...
Debian Bug report logs - #862205 libsndfile: CVE-2017-8361: global buffer overflow in flac_buffer_copy Package: src:libsndfile; Maintainer for src:libsndfile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 May 2017 19:03:02 UTC ...
Debian Bug report logs - #862203 libsndfile: CVE-2017-8363: heap-based buffer overflow in flac_buffer_copy Package: src:libsndfile; Maintainer for src:libsndfile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 May 2017 18:51:01 ...
Debian Bug report logs - #860255 libsndfile: CVE-2017-7742: Invalid memory read in flac_buffer_copy function Package: src:libsndfile; Maintainer for src:libsndfile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 13 Apr 2017 16:24:0 ...
Debian Bug report logs - #862204 libsndfile: CVE-2017-8362 Package: src:libsndfile; Maintainer for src:libsndfile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 May 2017 18:57:02 UTC Severity: important Tags: fixed-upstream, p ...
Debian Bug report logs - #862202 libsndfile: CVE-2017-8365 Package: src:libsndfile; Maintainer for src:libsndfile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 May 2017 18:45:01 UTC Severity: important Tags: fixed-upstream, p ...
In libsndfile before 1028, an error in the "flac_buffer_copy()" function (flacc) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585 ...