PT-2017-4325 · Secret Rabbit Code+3 · Libsamplerate+3
CVE-2017-7697
·
Publicado
2016-11-14
·
Atualizado
2022-11-29
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
libsamplerate versions prior to 0.1.9
Description:
The issue is related to a buffer over-read in the
calc output single function of the src sinc.c component in the Secret Rabbit Code library, which is used for audio sample rate conversion. This can be exploited by a remote attacker using a specially crafted audio file, potentially leading to a denial of service. The calc output single function is vulnerable to reading beyond the allowed boundaries of the data buffer.Recommendations:
For versions prior to 0.1.9, update to version 0.1.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
calc output single function in the src sinc.c component until a patch is available. Avoid using specially crafted audio files that could exploit this issue until the update is applied.Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Ubuntu
Libsamplerate