CVE-2017-6828: Buffer Overflow
Heap-based buffer overflow in audiofile allows remote attackers to have unspecified impact
Other sources
Heap-based buffer overflow in the readValue function in FileHandle.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted WAV file.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6828?
CVE-2017-6828 has been classified with a high severity due to the potential for remote exploitation via crafted WAV files.
How do I fix CVE-2017-6828?
To mitigate CVE-2017-6828, update to a version of the Audio File Library that addresses this buffer overflow vulnerability.
What is the vulnerable version of Audio File Library for CVE-2017-6828?
The vulnerable version of Audio File Library relating to CVE-2017-6828 is 0.3.6.
What types of attacks can CVE-2017-6828 lead to?
CVE-2017-6828 can potentially lead to arbitrary code execution or crashes on systems processing malicious WAV files.
Is CVE-2017-6828 exploitable remotely?
Yes, CVE-2017-6828 can be exploited remotely by attackers through specially crafted WAV files.