CVE-2017-8365: Medium severity libsndfile vulnerability
Published Apr 30, 2017
·Updated
The i2lesarray function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.
Affected Software
2 affected components
Libsndfile Project Libsndfile=1.0.28
Debian Debian Linux=8.0
Remediation
Event History
Apr 30, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8365?
CVE-2017-8365 is classified as a denial of service vulnerability due to potential application crashes.
2
How can CVE-2017-8365 affect my application?
CVE-2017-8365 can cause a buffer over-read leading to application crashes when processing crafted audio files.
3
Is my system vulnerable to CVE-2017-8365?
If you are using libsndfile version 1.0.28, your system is vulnerable to CVE-2017-8365.
4
What should I do to mitigate CVE-2017-8365?
To mitigate CVE-2017-8365, upgrade libsndfile to a version above 1.0.28.
5
Which software is affected by CVE-2017-8365?
CVE-2017-8365 specifically affects libsndfile version 1.0.28.