First published: Wed Oct 11 2017(Updated: )
In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libextractor | =1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15266 is rated as high severity due to the potential for causing application crashes.
To fix CVE-2017-15266, update to a version of GNU Libextractor that does not have this vulnerability.
Exploitation of CVE-2017-15266 occurs when processing a WAV file with a zero sample rate.
CVE-2017-15266 affects GNU Libextractor version 1.4 specifically.
CVE-2017-15266 does not lead to remote code execution but can cause application instability.