![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2017-18207 |
Description: | ** DISPUTED ** The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be prepared to handle a wide variety of exceptions." |
Test IDs: | 1.3.6.1.4.1.25623.1.1.4.2018.1786.1 1.3.6.1.4.1.25623.1.1.4.2018.0934.1 1.3.6.1.4.1.25623.1.1.4.2018.2040.1 1.3.6.1.4.1.25623.1.0.851827 1.3.6.1.4.1.25623.1.0.118271 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-18207 https://bugs.python.org/issue32056 SuSE Security Announcement: openSUSE-SU-2020:0086 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html |