CVE-2017-6892: Buffer Overflow
Published Jun 12, 2017
·Updated
In libsndfile version 1.0.28, an error in the "aiffreadchanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.
Affected Software
2 affected componentsFixes available
Libsndfile Project Libsndfile=1.0.28
debian/libsndfile
1.0.31-21.0.31-2+deb11u21.2.0-1+deb12u11.2.2-21.2.2-4
Remediation
Event History
Jun 12, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·10:38 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:57 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:58 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6892?
CVE-2017-6892 has a severity rating that suggests it can potentially allow for exploitation via out-of-bounds read memory access.
2
How do I fix CVE-2017-6892?
To fix CVE-2017-6892, update libsndfile to version 1.0.31-2, 1.2.0-1, or 1.2.2-1 and 1.2.2-2.
3
Which versions of libsndfile are affected by CVE-2017-6892?
CVE-2017-6892 affects libsndfile version 1.0.28.
4
Can CVE-2017-6892 lead to system compromise?
While CVE-2017-6892 can cause out-of-bounds read memory access, it doesn't automatically imply system compromise.
5
What types of files trigger CVE-2017-6892?
CVE-2017-6892 can be exploited through specially crafted AIFF files.