CVE-2017-14245

HIGH8.1EPSS 0.43%

libsndfile - security update

Published: 9/21/2017Modified: 4/28/2026
Also known as:DEBIAN-CVE-2017-14245

Description

An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.1CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

References (1)