CVE-2017-14245: High severity libsndfile vulnerability
An out of bounds read in the function d2alawarray() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14245?
CVE-2017-14245 has been classified as a medium severity vulnerability due to the potential for remote denial of service or information disclosure.
How do I fix CVE-2017-14245?
To fix CVE-2017-14245, upgrade to versions 1.0.31-2, 1.2.0-1, 1.2.2-1, or 1.2.2-2 of libsndfile.
What versions of libsndfile are affected by CVE-2017-14245?
CVE-2017-14245 affects libsndfile version 1.0.28 and any versions prior to the patched releases.
What kind of attack can exploit CVE-2017-14245?
CVE-2017-14245 may lead to a remote denial of service (DoS) attack or cause information disclosure.
Is CVE-2017-14245 specific to any operating system?
CVE-2017-14245 is primarily associated with Debian GNU/Linux version 8.0 when using the vulnerable libsndfile package.