CVE-2017-14246: High severity libsndfile vulnerability
Published Sep 21, 2017
·Updated
An out of bounds read in the function d2ulawarray() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.
Affected Software
3 affected componentsFixes available
debian/libsndfile
1.0.31-21.2.0-11.2.2-11.2.2-2
Libsndfile Project Libsndfile=1.0.28
Debian Debian Linux=8.0
Remediation
Event History
Sep 21, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:28 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:42 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-14246?
CVE-2017-14246 has a severity rating that indicates a potential for remote denial of service (DoS) or information disclosure.
2
How do I fix CVE-2017-14246?
To fix CVE-2017-14246, upgrade to libsndfile version 1.0.31-2 or later.
3
What versions of libsndfile are affected by CVE-2017-14246?
CVE-2017-14246 affects libsndfile version 1.0.28.
4
Can CVE-2017-14246 lead to user data exposure?
Yes, CVE-2017-14246 can lead to information disclosure through mishandling of floating-point values.
5
What software is vulnerable to CVE-2017-14246?
CVE-2017-14246 specifically affects the libsndfile library version 1.0.28.