PoC Index

CVE-2017-7742

MEDIUM 5.5EPSS 1.4%

In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with read memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

CVSS v3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS
1.39% chance of exploitation in the next 30 days, 70th percentile
Published
2017-04-12
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related