CVE-2017-14634: Divide by Zero
Published Sep 21, 2017
·Updated
In libsndfile 1.0.28, a divide-by-zero error exists in the function double64init() in double64.c, which may lead to DoS when playing a crafted audio file.
Affected Software
3 affected componentsFixes available
debian/libsndfile
1.0.31-21.2.0-11.2.2-1
Libsndfile Project Libsndfile=1.0.28
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Sep 21, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:30 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:42 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-14634?
CVE-2017-14634 is classified as a DoS vulnerability due to a divide-by-zero error that can occur in libsndfile.
2
How do I fix CVE-2017-14634?
To fix CVE-2017-14634, upgrade libsndfile to version 1.0.31-2, 1.2.0-1, or 1.2.2-1.
3
What software is affected by CVE-2017-14634?
CVE-2017-14634 affects libsndfile version 1.0.28 and any software that depends on it.
4
Can CVE-2017-14634 lead to data loss?
CVE-2017-14634 primarily leads to denial of service and does not indicate direct data loss but may disrupt service availability.
5
What is the impact of exploiting CVE-2017-14634?
Exploiting CVE-2017-14634 can cause programs using libsndfile to crash when processing a maliciously crafted audio file.