Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
{ "vanir_signatures": [ { "id": "CVE-2017-6838-0b30c72a", "signature_type": "Function", "target": { "file": "sfcommands/sfconvert.c", "function": "copyaudiodata" }, "signature_version": "v1", "digest": { "length": 690.0, "function_hash": "11928935868487764216599788861433179953" }, "deprecated": false, "source": "https://github.com/antlarr/audiofile/commit/7d65f89defb092b63bcbc5d98349fb222ca73b3c" }, { "id": "CVE-2017-6838-a2ee6a52", "signature_type": "Line", "target": { "file": "sfcommands/sfconvert.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "150918354625819740051003512373224212013", "26581543356970238686948986881481173521", "95340238861390683713590756590485121383", "76099634027226077542197166596315184811", "60148152594538939281170523359972027744", "73371561367739945972798040661710927992", "119561788308632664851648660764826611068", "262657216346216445159424217710771616941" ], "threshold": 0.9 }, "deprecated": false, "source": "https://github.com/antlarr/audiofile/commit/7d65f89defb092b63bcbc5d98349fb222ca73b3c" } ] }