PublicDateAtUSN: 2017-06-12 Candidate: CVE-2017-6892 PublicDate: 2017-06-12 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6892 https://secuniaresearch.flexerasoftware.com/advisories/76717/ https://secuniaresearch.flexerasoftware.com/secunia_research/2017-13/ https://ubuntu.com/security/notices/USN-4013-1 https://ubuntu.com/security/notices/USN-4704-1 Description: In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864704 Priority: low Discovered-by: Laurent Delosieres Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_libsndfile: upstream: https://github.com/erikd/libsndfile/commit/f833c53cb596e9e1792949f762e0b33661822748 upstream_libsndfile: released (1.0.28-1) precise/esm_libsndfile: DNE trusty_libsndfile: ignored (reached end-of-life) trusty/esm_libsndfile: released (1.0.25-7ubuntu2.2+esm1) vivid/stable-phone-overlay_libsndfile: ignored (reached end-of-life) vivid/ubuntu-core_libsndfile: DNE xenial_libsndfile: released (1.0.25-10ubuntu0.16.04.2) esm-infra/xenial_libsndfile: released (1.0.25-10ubuntu0.16.04.2) yakkety_libsndfile: ignored (reached end-of-life) zesty_libsndfile: ignored (reached end-of-life) artful_libsndfile: not-affected (1.0.28-3) bionic_libsndfile: not-affected (1.0.28-3) cosmic_libsndfile: not-affected (1.0.28-3) disco_libsndfile: not-affected (1.0.28-3) eoan_libsndfile: not-affected (1.0.28-3) focal_libsndfile: not-affected (1.0.28-3) groovy_libsndfile: not-affected (1.0.28-3) devel_libsndfile: not-affected (1.0.28-3)