First published: Wed Nov 29 2017(Updated: )
In aubio 0.4.6, a divide-by-zero error exists in the function `new_aubio_source_wavread()` in source_wavread.c, which may lead to DoS when playing a crafted audio file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/aubio | <0.4.7 | 0.4.7 |
Aubio Aubio | =0.4.6 | |
debian/aubio | 0.4.9-4 0.4.9-4.3 0.4.9-4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17054 is a vulnerability in aubio 0.4.6 that allows for a divide-by-zero error, leading to denial of service (DoS) when playing a crafted audio file.
CVE-2017-17054 has a severity rating of 5.5 (High).
aubio versions 0.4.6 and earlier are affected by CVE-2017-17054.
To fix CVE-2017-17054, upgrade to aubio version 0.4.7 or later.
You can find more information about CVE-2017-17054 at the following references: [link1](https://github.com/aubio/aubio/issues/148), [link2](https://security-tracker.debian.org/tracker/CVE-2017-17054), [link3](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17054)