CVE-2017-6892

HIGH8.8EPSS 0.96%

libsndfile - security update

Published: 6/12/2017Modified: 4/28/2026
Also known as:DEBIAN-CVE-2017-6892

Description

In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References (1)