CVE-2017-7585: Buffer Overflow
Published Apr 7, 2017
·Updated
In libsndfile before 1.0.28, an error in the "flacbuffercopy()" function (flac.c) can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.
Affected Software
1 affected component
Libsndfile Project Libsndfile<=1.0.27
Remediation
Event History
Apr 7, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7585?
CVE-2017-7585 has been classified with a medium severity due to its potential for stack-based buffer overflow exploitation.
2
How do I fix CVE-2017-7585?
To fix CVE-2017-7585, you should upgrade to libsndfile version 1.0.28 or later.
3
What software is affected by CVE-2017-7585?
CVE-2017-7585 affects libsndfile versions up to and including 1.0.27.
4
What type of attack does CVE-2017-7585 enable?
CVE-2017-7585 allows for a stack-based buffer overflow attack when processing specially crafted FLAC files.
5
Is CVE-2017-7585 vulnerability present in later versions of libsndfile?
No, CVE-2017-7585 is not present in libsndfile versions 1.0.28 and later.