First published: Tue Dec 12 2017(Updated: )
The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aubio Aubio | =0.4.6 | |
FFmpeg FFmpeg | =3.4.1 | |
FFmpeg libswresample | <=3.0.101 | |
debian/aubio | 0.4.9-4 0.4.9-4.3 0.4.9-4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-17555 is medium.
Aubio versions 0.4.6-2, 0.4.9-4, and 0.4.9-4.3 are affected by CVE-2017-17555.
FFmpeg version 3.4.1 is affected by CVE-2017-17555.
The recommended remedy for CVE-2017-17555 in Aubio is to update to version 0.4.9-4.3.
The recommended remedy for CVE-2017-17555 in FFmpeg is to update to a version beyond 3.0.101.