Vulnerability Description
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libsamplerate Project | Libsamplerate | <= 0.1.8 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/97587Broken Link
- https://github.com/erikd/libsamplerate/issues/11Issue TrackingPatch
- https://lists.debian.org/debian-lts-announce/2021/12/msg00010.htmlMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/97587Broken Link
- https://github.com/erikd/libsamplerate/issues/11Issue TrackingPatch
- https://lists.debian.org/debian-lts-announce/2021/12/msg00010.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2017-7697?
CVE-2017-7697 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
How severe is CVE-2017-7697?
CVE-2017-7697 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7697?
Check the references section above for vendor advisories and patch information. Affected products include: Libsamplerate Project Libsamplerate, Debian Debian Linux.