CVE-2017-11548: Buffer Overflow
Published Jul 31, 2017
·Updated
The tokenizematrix function in audioout.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service
Affected Software
3 affected componentsFixes available
debian/libao<=1.2.2+20180113-1.1, <=1.2.2+20180113-1.2
xiph libao=1.2.0
Microsoft cbl2 libao 1.2.0-24
Event History
Jul 31, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Aug 3, 2017
Data Sourced
via Debian·11:15 AM
SeverityAffected Software
Oct 1, 2025
Data Sourced
via Microsoft·11:10 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:10 PM
Affected Software
Updated
via Microsoft·11:10 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2017-11548?
CVE-2017-11548 has a severity rating that indicates it can cause denial of service due to memory corruption.
2
How do I fix CVE-2017-11548?
To fix CVE-2017-11548, update libao to version 1.2.2 or later.
3
Which versions of libao are affected by CVE-2017-11548?
CVE-2017-11548 affects libao version 1.2.0.
4
Can CVE-2017-11548 be exploited remotely?
Yes, CVE-2017-11548 can be exploited remotely through a crafted MP3 file.
5
What component of libao is vulnerable in CVE-2017-11548?
The _tokenize_matrix function in audio_out.c is the vulnerable component in libao for CVE-2017-11548.