WAVE.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via vectors related to a large number of coefficients.
{ "vanir_signatures": [ { "digest": { "function_hash": "90884721003669009012809751076469776921", "length": 5810.0 }, "id": "CVE-2017-6837-004e2484", "source": "https://github.com/antlarr/audiofile/commit/c48e4c6503f7dabd41f11d4c9c7b7f8960e7f2c0", "signature_type": "Function", "signature_version": "v1", "target": { "file": "libaudiofile/WAVE.cpp", "function": "WAVEFile::parseFormat" }, "deprecated": false }, { "digest": { "threshold": 0.9, "line_hashes": [ "13621263558501112254747353303220762784", "104004621141017741708021226667712075629", "52230882242202547986524107444458227182", "310219025358696948157569348240462368149" ] }, "id": "CVE-2017-6837-c8d02805", "source": "https://github.com/antlarr/audiofile/commit/c48e4c6503f7dabd41f11d4c9c7b7f8960e7f2c0", "signature_type": "Line", "signature_version": "v1", "target": { "file": "libaudiofile/WAVE.cpp" }, "deprecated": false } ] }