Wind River Support Network

HomeDefectsLIN7-9280
Fixed

LIN7-9280 : Security Advisory - libsndfile - CVE-2017-17456

Created: Dec 14, 2017    Updated: May 18, 2019
Resolved Date: Apr 2, 2019
Found In Version: 7.0.0.27
Fix Version: 7.0.0.30
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

The function d2alaw_array() in alaw.c of libsndfile 1.0.29pre1 may lead to a remote DoS attack (SEGV on unknown address 0x000000000000), a different vulnerability than CVE-2017-14245.

https://nvd.nist.gov/vuln/detail/CVE-2017-17456

CVEs


Live chat
Online