Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.843105
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-3241-1)
Summary:The remote host is missing an update for the 'audiofile' package(s) announced via the USN-3241-1 advisory.
Description:Summary:
The remote host is missing an update for the 'audiofile' package(s) announced via the USN-3241-1 advisory.

Vulnerability Insight:
Agostino Sarubbo discovered that audiofile incorrectly handled certain
malformed audio files. If a user or automated system were tricked into
processing a specially crafted audio file, a remote attacker could cause
applications linked against audiofile to crash, leading to a denial of
service, or possibly execute arbitrary code.

Affected Software/OS:
'audiofile' package(s) on Ubuntu 12.04, Ubuntu 14.04.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-6827
Debian Security Information: DSA-3814 (Google Search)
http://www.debian.org/security/2017/dsa-3814
https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-msadpcminitializecoefficients-msadpcm-cpp/
Common Vulnerability Exposure (CVE) ID: CVE-2017-6828
BugTraq ID: 97183
http://www.securityfocus.com/bid/97183
https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-readvalue-filehandle-cpp/
Common Vulnerability Exposure (CVE) ID: CVE-2017-6829
BugTraq ID: 97189
http://www.securityfocus.com/bid/97189
https://blogs.gentoo.org/ago/2017/02/20/audiofile-global-buffer-overflow-in-decodesample-ima-cpp/
https://github.com/antlarr/audiofile/commit/25eb00ce913452c2e614548d7df93070bf0d066f
https://github.com/mpruett/audiofile/issues/33
http://www.openwall.com/lists/oss-security/2017/03/13/1
Common Vulnerability Exposure (CVE) ID: CVE-2017-6830
https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-alaw2linear_buf-g711-cpp/
https://github.com/mpruett/audiofile/issues/34
https://github.com/mpruett/audiofile/pull/42
http://www.openwall.com/lists/oss-security/2017/03/13/2
Common Vulnerability Exposure (CVE) ID: CVE-2017-6831
BugTraq ID: 97588
http://www.securityfocus.com/bid/97588
https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-imadecodeblockwave-ima-cpp/
https://github.com/Hack-Me/Pocs_for_Multi_Versions/tree/main/CVE-2017-6831
https://github.com/antlarr/audiofile/commit/a2e9eab8ea87c4ffc494d839ebb4ea145eb9f2e6
https://github.com/mpruett/audiofile/issues/35
http://www.openwall.com/lists/oss-security/2017/03/13/3
Common Vulnerability Exposure (CVE) ID: CVE-2017-6832
BugTraq ID: 97589
http://www.securityfocus.com/bid/97589
https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-msadpcmdecodeblock-msadpcm-cpp/
https://github.com/mpruett/audiofile/issues/36
http://www.openwall.com/lists/oss-security/2017/03/13/4
Common Vulnerability Exposure (CVE) ID: CVE-2017-6833
https://blogs.gentoo.org/ago/2017/02/20/audiofile-divide-by-zero-in-blockcodecrunpull-blockcodec-cpp/
https://github.com/mpruett/audiofile/issues/37
http://www.openwall.com/lists/oss-security/2017/03/13/5
Common Vulnerability Exposure (CVE) ID: CVE-2017-6834
https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-ulaw2linear_buf-g711-cpp/
https://github.com/mpruett/audiofile/issues/38
http://www.openwall.com/lists/oss-security/2017/03/13/6
Common Vulnerability Exposure (CVE) ID: CVE-2017-6835
https://blogs.gentoo.org/ago/2017/02/20/audiofile-divide-by-zero-in-blockcodecreset1-blockcodec-cpp/
https://github.com/mpruett/audiofile/issues/39
http://www.openwall.com/lists/oss-security/2017/03/13/7
Common Vulnerability Exposure (CVE) ID: CVE-2017-6836
https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-expand3to4modulerun-simplemodule-h/
https://github.com/mpruett/audiofile/issues/40
http://www.openwall.com/lists/oss-security/2017/03/13/8
Common Vulnerability Exposure (CVE) ID: CVE-2017-6837
BugTraq ID: 97314
http://www.securityfocus.com/bid/97314
https://blogs.gentoo.org/ago/2017/02/20/audiofile-multiple-ubsan-crashes/
https://github.com/antlarr/audiofile/commit/c48e4c6503f7dabd41f11d4c9c7b7f8960e7f2c0
https://github.com/mpruett/audiofile/issues/41
http://www.openwall.com/lists/oss-security/2017/03/13/9
Common Vulnerability Exposure (CVE) ID: CVE-2017-6838
https://github.com/antlarr/audiofile/commit/7d65f89defb092b63bcbc5d98349fb222ca73b3c
Common Vulnerability Exposure (CVE) ID: CVE-2017-6839
https://github.com/antlarr/audiofile/commit/beacc44eb8cdf6d58717ec1a5103c5141f1b37f9
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.