Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6838.json"
[
{
"target": {
"function": "copyaudiodata",
"file": "sfcommands/sfconvert.c"
},
"id": "CVE-2017-6838-0b30c72a",
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/antlarr/audiofile/commit/7d65f89defb092b63bcbc5d98349fb222ca73b3c",
"signature_version": "v1",
"digest": {
"function_hash": "11928935868487764216599788861433179953",
"length": 690.0
}
},
{
"target": {
"file": "sfcommands/sfconvert.c"
},
"id": "CVE-2017-6838-a2ee6a52",
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/antlarr/audiofile/commit/7d65f89defb092b63bcbc5d98349fb222ca73b3c",
"signature_version": "v1",
"digest": {
"line_hashes": [
"150918354625819740051003512373224212013",
"26581543356970238686948986881481173521",
"95340238861390683713590756590485121383",
"76099634027226077542197166596315184811",
"60148152594538939281170523359972027744",
"73371561367739945972798040661710927992",
"119561788308632664851648660764826611068",
"262657216346216445159424217710771616941"
],
"threshold": 0.9
}
}
]