Debian 10225 Published by

Updated audiofile packages has been released for Debian 7 LTS



Package : audiofile
Version : 0.3.4-2+deb7u1
CVE ID : CVE-2017-6829 CVE-2017-6830 CVE-2017-6831 CVE-2017-6832
CVE-2017-6833 CVE-2017-6834 CVE-2017-6835 CVE-2017-6836
CVE-2017-6837 CVE-2017-6838 CVE-2017-6839
Debian Bug : 857651


Multiple vulnerabilities has been found in audiofile.

CVE-2017-6829

Allows remote attackers to cause a denial of service (crash) via a
crafted file.

CVE-2017-6830, CVE-2017-6834, CVE-2017-6831, CVE-2017-6832, CVE-2017-6838,
CVE-2017-6839, CVE-2017-6836

Heap-based buffer overflow in that allows remote attackers to cause
a denial of service (crash) via a crafted file.

CVE-2017-6833, CVE-2017-6835

The runPull function allows remote attackers to cause a denial of
service (divide-by-zero error and crash) via a crafted file.

CVE-2017-6837

Allows remote attackers to cause a denial of service (crash) via
vectors related to a large number of coefficients.

For Debian 7 "Wheezy", these problems have been fixed in version
0.3.4-2+deb7u1.

We recommend that you upgrade your audiofile packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
  Audiofile security update for Debian 7 LTS