Back to Database
Status published
High
CVE-2017-6892
In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function...
Vulnerability Description
In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-6892
Credits & Attribution
No credits recorded in the NVD database.
References
- https://secuniaresearch.flexerasoftware.com/secunia_research/2017-13/
- https://secuniaresearch.flexerasoftware.com/advisories/76717/
- https://github.com/erikd/libsndfile/commit/f833c53cb596e9e1792949f762e0b33661822748
- https://security.gentoo.org/glsa/201811-23
- https://usn.ubuntu.com/4013-1/
- https://lists.debian.org/debian-lts-announce/2020/10/msg00030.html
More from Flexera Software LLC
View All →CVE-2018-5819
An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions...
High
7.5
CVE-2018-5817
A type confusion error within the "unpacked_load_raw()" function within LibRaw...
High
7.5
CVE-2018-20034
A Denial of Service vulnerability related to adding an item...
High
7.5
CVE-2018-20033
A Remote Code Execution vulnerability in lmgrd and vendor daemon...
Critical
9.8
CVE-2018-20032
A Denial of Service vulnerability related to message decoding in...
High
7.5
Affected Vendor
Flexera Software LLC
View all reports →Affected Software
libsndfile
Vulnerable Versions:
1.0.28
Timeline
Official Publish:
June 12th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.