First published: Wed Feb 19 2020(Updated: )
Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =15.04 | |
Ubuntu | =15.10 | |
Fedora | =23 | |
Audio File Library | <0.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7747 has a severity rating that indicates it can cause a denial of service and possibly remote code execution.
To fix CVE-2015-7747, update the affected audiofile library to a version that addresses the buffer overflow vulnerability.
CVE-2015-7747 affects audiofile library versions up to 0.3.6 and specific Ubuntu and Fedora versions including Ubuntu 12.04, 14.04, 15.04, 15.10, and Fedora 23.
CVE-2015-7747 is classified as a buffer overflow vulnerability.
CVE-2015-7747 can be exploited by user-assisted remote attackers through specially crafted audio files.