Wind River Support Network

HomeDefectsLIN6-14090
Fixed

LIN6-14090 : Security Advisory - libsndfile - CVE-2017-17456

Created: Dec 14, 2017    Updated: Jun 3, 2019
Resolved Date: Mar 12, 2019
Found In Version: 6.0.0.35
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

The function d2alaw_array() in alaw.c of libsndfile 1.0.29pre1 may lead to a remote DoS attack (SEGV on unknown address 0x000000000000), a different vulnerability than CVE-2017-14245.

https://nvd.nist.gov/vuln/detail/CVE-2017-17456
Live chat
Online