CVE-2017-6831

Source
https://cve.org/CVERecord?id=CVE-2017-6831
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-6831.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-6831
Downstream
Related
Published
2017-03-20T16:59:02.703Z
Modified
2026-02-02T14:48:05.903701Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Heap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 and 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.

References

Affected packages

Git / github.com/antlarr/audiofile

Affected ranges

Type
GIT
Repo
https://github.com/antlarr/audiofile
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

audiofile-0.*
audiofile-0.2.1
audiofile-0.2.2
audiofile-0.2.3
audiofile-0.2.4
audiofile-0.2.5
audiofile-0.2.6
audiofile-0.2.7
audiofile-0.3.0
audiofile-0.3.1
audiofile-0.3.2
audiofile-0.3.3
audiofile-0.3.4
audiofile-0.3.5
audiofile-0.3.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-6831.json"
vanir_signatures
[
    {
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/antlarr/audiofile/commit/a2e9eab8ea87c4ffc494d839ebb4ea145eb9f2e6",
        "target": {
            "file": "libaudiofile/WAVE.cpp"
        },
        "deprecated": false,
        "id": "CVE-2017-6831-314568ec",
        "digest": {
            "line_hashes": [
                "331470145967194600774318625752253890445",
                "232798939947800200754239479194282584567",
                "219950778595101875391487318990529141915",
                "9931794692818815536740976616195528411",
                "313616948841340480450728645639032661791",
                "185358438352405145440304294832130766911",
                "668093673687982700959098601548676743",
                "221765431166475582793187396825314521101"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/antlarr/audiofile/commit/a2e9eab8ea87c4ffc494d839ebb4ea145eb9f2e6",
        "target": {
            "function": "WAVEFile::parseFormat",
            "file": "libaudiofile/WAVE.cpp"
        },
        "deprecated": false,
        "id": "CVE-2017-6831-571136c3",
        "digest": {
            "length": 5810.0,
            "function_hash": "90884721003669009012809751076469776921"
        }
    }
]

Git / github.com/mpruett/audiofile

Affected ranges

Type
GIT
Repo
https://github.com/mpruett/audiofile
Events
Introduced
0 Unknown introduced commit / All previous commits are affected

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-6831.json"