The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
{ "vanir_signatures": [ { "deprecated": false, "signature_type": "Line", "source": "https://github.com/antlarr/audiofile/commit/25eb00ce913452c2e614548d7df93070bf0d066f", "target": { "file": "libaudiofile/modules/IMA.cpp" }, "signature_version": "v1", "digest": { "threshold": 0.9, "line_hashes": [ "314412711357247611739050889297020008883", "308376905490334417346154015126452199650", "315545262704911627105280591272180543736", "59034921127239373195419642679023914898", "70896150444897847407704141453378246150", "5805291424995724120988277229990810891", "92682803366079013387578263451143302774", "165657437472454506597266258804641466488" ] }, "id": "CVE-2017-6829-2e061dd3" }, { "deprecated": false, "signature_type": "Function", "source": "https://github.com/antlarr/audiofile/commit/25eb00ce913452c2e614548d7df93070bf0d066f", "target": { "file": "libaudiofile/modules/IMA.cpp", "function": "IMA::decodeBlockQT" }, "signature_version": "v1", "digest": { "function_hash": "231660243917669039974652213955886210184", "length": 645.0 }, "id": "CVE-2017-6829-47736fd0" }, { "deprecated": false, "signature_type": "Function", "source": "https://github.com/antlarr/audiofile/commit/25eb00ce913452c2e614548d7df93070bf0d066f", "target": { "file": "libaudiofile/modules/IMA.cpp", "function": "IMA::decodeBlockWAVE" }, "signature_version": "v1", "digest": { "function_hash": "114892683652434953785715127113324955944", "length": 828.0 }, "id": "CVE-2017-6829-5a4a6dfc" } ] }