CVE-2017-16942: Divide by Zero
Published Nov 25, 2017
·Updated
In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the function wavw64readfmtchunk() in wavw64.c, which may lead to DoS when playing a crafted audio file.
Affected Software
2 affected componentsFixes available
Libsndfile Project Libsndfile=1.0.25
debian/libsndfile
1.0.31-21.0.31-2+deb11u21.2.0-1+deb12u11.2.2-21.2.2-4
Remediation
Event History
Nov 25, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:32 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:57 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:58 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-16942?
CVE-2017-16942 has the potential to cause a Denial of Service (DoS) when handling crafted audio files.
2
How do I fix CVE-2017-16942?
To fix CVE-2017-16942, upgrade to libsndfile version 1.0.26 or later.
3
Which versions of libsndfile are affected by CVE-2017-16942?
CVE-2017-16942 affects libsndfile version 1.0.25 and prior versions.
4
Is CVE-2017-16942 related to audio file handling?
Yes, CVE-2017-16942 is associated with a divide-by-zero error when processing specific audio files.
5
What can happen if CVE-2017-16942 is exploited?
If exploited, CVE-2017-16942 can result in a crash of the application playing the vulnerable audio files.