Lucene search

K
cveMitreCVE-2017-14246
HistorySep 21, 2017 - 1:29 p.m.

CVE-2017-14246

2017-09-2113:29:00
CWE-125
mitre
web.nvd.nist.gov
117
2
cve-2017-14246
out of bounds read
libsndfile
remote dos attack
information disclosure
nvd

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0.004

Percentile

74.9%

An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

Affected configurations

Nvd
Node
libsndfile_projectlibsndfileMatch1.0.28
Node
debiandebian_linuxMatch8.0
VendorProductVersionCPE
libsndfile_projectlibsndfile1.0.28cpe:2.3:a:libsndfile_project:libsndfile:1.0.28:*:*:*:*:*:*:*
debiandebian_linux8.0cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Social References

More

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0.004

Percentile

74.9%