Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2017-14245

Published: 21 September 2017

An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

Notes

AuthorNote
leosilva
reproducer can be found in github link
mdeslaur
a-ulaw-fix-multiple-buffer-overflows-432.patch

Priority

Low

CVSS 3 base score: 8.1

Status

Package Release Status
libsndfile
Launchpad, Ubuntu, Debian
artful Ignored
(reached end-of-life)
bionic
Released (1.0.28-4ubuntu0.18.04.1)
cosmic
Released (1.0.28-4ubuntu0.18.10.1)
disco Not vulnerable
(1.0.28-6)
eoan Not vulnerable
(1.0.28-6)
focal Not vulnerable
(1.0.28-6)
groovy Not vulnerable
(1.0.28-6)
precise Does not exist

trusty
Released (1.0.25-7ubuntu2.2+esm1)
upstream
Released (1.0.28-5)
xenial
Released (1.0.25-10ubuntu0.16.04.2)
zesty Ignored
(reached end-of-life)
Patches:
upstream: https://github.com/erikd/libsndfile/commit/8ddc442d539ca775d80cdbc7af17a718634a743f