CVE-2017-7586: Buffer Overflow
Published Apr 7, 2017
·Updated
In libsndfile before 1.0.28, an error in the "headerread()" function (common.c) when handling ID3 tags can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.
Affected Software
1 affected component
Libsndfile Project Libsndfile<=1.0.27
Remediation
Event History
Apr 7, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7586?
CVE-2017-7586 has a high severity rating due to the potential for a stack-based buffer overflow.
2
How do I fix CVE-2017-7586?
To fix CVE-2017-7586, upgrade libsndfile to version 1.0.28 or later.
3
What types of files are affected by CVE-2017-7586?
CVE-2017-7586 affects specially crafted FLAC files containing malformed ID3 tags.
4
Who is affected by CVE-2017-7586?
Users and applications utilizing libsndfile versions prior to 1.0.28 are affected by CVE-2017-7586.
5
What can be compromised due to CVE-2017-7586?
CVE-2017-7586 can lead to application crashes, arbitrary code execution, or exploitation of vulnerable systems.