Wind River Support Network

HomeDefectsLIN8-8353
Fixed

LIN8-8353 : Security Advisory - libsndfile - CVE-2017-17456

Created: Dec 14, 2017    Updated: Mar 13, 2019
Resolved Date: Mar 3, 2019
Found In Version: 8.0.0.24
Fix Version: 8.0.0.30
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

The function d2alaw_array() in alaw.c of libsndfile 1.0.29pre1 may lead to a remote DoS attack (SEGV on unknown address 0x000000000000), a different vulnerability than CVE-2017-14245.

https://nvd.nist.gov/vuln/detail/CVE-2017-17456

CVEs


Live chat
Online