CVE-2016-2540: Buffer Overflow
Published Feb 7, 2018
·Updated
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHUNK structure.
Affected Software
1 affected component
Audacityteam Audacity<2.1.2
Event History
Feb 7, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2540?
CVE-2016-2540 has a medium severity rating due to its potential to cause denial of service through memory corruption.
2
How do I fix CVE-2016-2540?
To fix CVE-2016-2540, upgrade to Audacity version 2.1.2 or later.
3
What kind of attack is possible with CVE-2016-2540?
CVE-2016-2540 allows remote attackers to perform a denial of service attack by exploiting a crafted FORMATCHUNK structure.
4
Which versions of Audacity are affected by CVE-2016-2540?
Audacity versions prior to 2.1.2 are affected by CVE-2016-2540.
5
What happens if CVE-2016-2540 is exploited?
Exploitation of CVE-2016-2540 can lead to memory corruption and crashes of the Audacity application.