The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
[
{
"id": "CVE-2017-6829-2e061dd3",
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "libaudiofile/modules/IMA.cpp"
},
"source": "https://github.com/antlarr/audiofile/commit/25eb00ce913452c2e614548d7df93070bf0d066f",
"signature_version": "v1",
"digest": {
"line_hashes": [
"314412711357247611739050889297020008883",
"308376905490334417346154015126452199650",
"315545262704911627105280591272180543736",
"59034921127239373195419642679023914898",
"70896150444897847407704141453378246150",
"5805291424995724120988277229990810891",
"92682803366079013387578263451143302774",
"165657437472454506597266258804641466488"
],
"threshold": 0.9
}
},
{
"id": "CVE-2017-6829-47736fd0",
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "libaudiofile/modules/IMA.cpp",
"function": "IMA::decodeBlockQT"
},
"source": "https://github.com/antlarr/audiofile/commit/25eb00ce913452c2e614548d7df93070bf0d066f",
"signature_version": "v1",
"digest": {
"length": 645.0,
"function_hash": "231660243917669039974652213955886210184"
}
},
{
"id": "CVE-2017-6829-5a4a6dfc",
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "libaudiofile/modules/IMA.cpp",
"function": "IMA::decodeBlockWAVE"
},
"source": "https://github.com/antlarr/audiofile/commit/25eb00ce913452c2e614548d7df93070bf0d066f",
"signature_version": "v1",
"digest": {
"length": 828.0,
"function_hash": "114892683652434953785715127113324955944"
}
}
]