Vulnerability Name:

CVE-2017-12562 (CCN-130318)

Assigned:2017-07-14
Published:2017-07-14
Updated:2022-12-02
Summary:
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.8 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
5.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-12562

Source: XF
Type: UNKNOWN
libsndfil-cve201712562-bo(130318)

Source: CCN
Type: libsndfile GIT Repository
Heap buffer overflows in `psf_binheader_writef` in 1.0.28 and later #292

Source: cve@mitre.org
Type: Issue Tracking, Patch, Third Party Advisory
cve@mitre.org

Source: CCN
Type: libsndfile GIT Repository
src/common.c: Fix heap buffer overflows when writing strings in binhe… · manxorist/libsndfile@b6a9d7e · GitHub

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Third Party Advisory
cve@mitre.org

Oval Definitions
Definition IDClassTitleLast Modified
oval:org.opensuse.security:def:201712562
V
CVE-2017-12562
2023-06-22
oval:org.opensuse.security:def:7668
P
libsndfile-devel-1.0.28-150000.5.17.1 on GA media (Moderate)
2023-06-12
oval:org.opensuse.security:def:792
P
Security update for webkit2gtk3 (Important)
2022-10-01
oval:org.opensuse.security:def:3077
P
gdm-3.10.0.1-54.6.3 on GA media (Moderate)
2022-06-28
oval:org.opensuse.security:def:94707
P
libsndfile-devel-1.0.28-5.15.1 on GA media (Moderate)
2022-06-22
oval:org.opensuse.security:def:198
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2022-06-13
oval:org.opensuse.security:def:194
P
libseccomp-devel-2.4.1-3.3.1 on GA media (Moderate)
2022-06-13
oval:org.opensuse.security:def:483
P
Security update for nodejs8 (Moderate)
2022-05-17
oval:org.opensuse.security:def:93848
P
(Important)
2022-03-07
oval:org.opensuse.security:def:112833
P
libsndfile-devel-1.0.31-2.2 on GA media (Moderate)
2022-01-17
oval:org.opensuse.security:def:1127
P
Security update for go1.16 (Important)
2021-10-06
oval:org.opensuse.security:def:106298
P
libsndfile-devel-1.0.31-2.2 on GA media (Moderate)
2021-10-01
oval:org.opensuse.security:def:71313
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2021-09-21
oval:org.opensuse.security:def:103382
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2021-09-21
oval:org.opensuse.security:def:61572
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2021-09-21
oval:org.opensuse.security:def:96692
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2021-09-21
oval:org.opensuse.security:def:89727
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2021-09-21
oval:org.opensuse.security:def:47333
P
libass5-0.10.2-3.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:48232
P
libz1-1.2.11-9.42 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47776
P
libquicktime0-1.2.4-14.3.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47557
P
apache2-mod_perl-2.0.8-11.43 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47872
P
python3-requests-2.7.0-2.3 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47919
P
xalan-j2-2.7.0-264.133 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47176
P
wget-1.14-10.3 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47005
P
libXxf86vm1-1.1.3-3.53 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:48065
P
libICE6-1.0.8-12.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47416
P
libtag1-1.9.1-1.218 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47140
P
python-requests-2.8.1-6.11.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:48161
P
libopenssl-devel-1.0.2p-1.13 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47714
P
libgssglue1-0.4-3.76 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47465
P
perl-DBD-mysql-4.021-11.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47841
P
pam-modules-12.1-23.12 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47705
P
libexif12-0.6.21-8.3.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47044
P
libltdl7-2.4.2-14.30 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47004
P
libXxf86dga1-1.1.4-3.58 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47943
P
accountsservice-0.6.42-16.3.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:48003
P
evince-3.20.2-6.27.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47268
P
gnome-keyring-3.20.0-27.2 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47019
P
libfreetype6-2.6.3-7.8.2 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:48130
P
libjasper1-1.900.14-195.15.1 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:47630
P
groff-1.22.2-5.287 on GA media (Moderate)
2021-08-16
oval:org.opensuse.security:def:100994
P
libsndfile1-32bit-1.0.28-5.5.1 on GA media (Moderate)
2021-08-10
oval:org.opensuse.security:def:63437
P
libsndfile1-32bit-1.0.28-5.5.1 on GA media (Moderate)
2021-08-10
oval:org.opensuse.security:def:94281
P
libsndfile1-32bit-1.0.28-5.5.1 on GA media (Moderate)
2021-08-10
oval:org.opensuse.security:def:2348
P
libsndfile1-32bit-1.0.28-5.5.1 on GA media (Moderate)
2021-08-10
oval:org.opensuse.security:def:63493
P
libsndfile1-32bit-1.0.28-5.5.1 on GA media (Moderate)
2021-08-10
oval:org.opensuse.security:def:2404
P
libsndfile1-32bit-1.0.28-5.5.1 on GA media (Moderate)
2021-08-10
oval:org.opensuse.security:def:107660
P
libsndfile1-32bit-1.0.28-5.5.1 on GA media (Moderate)
2021-08-10
oval:org.opensuse.security:def:100974
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2021-08-09
oval:org.opensuse.security:def:71957
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2021-08-09
oval:org.opensuse.security:def:62216
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2021-08-09
oval:org.opensuse.security:def:69884
P
Security update for arpwatch (Important)
2021-06-28
oval:org.opensuse.security:def:48924
P
libgadu3-1.11.4-1.12 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:46716
P
libarchive13-3.1.2-9.1 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:61283
P
libsndfile-devel-1.0.28-3.24 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:46851
P
sysconfig-0.83.8-7.1 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:71083
P
python2-paramiko-2.4.1-1.15 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:48581
P
opensc-0.13.0-1.107 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:70970
P
libevent-2_1-8-2.1.8-2.23 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:46715
P
libapr1-1.5.1-2.7 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:48870
P
libreoffice-5.2.5.1-42.13 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:46730
P
libgssglue1-0.4-3.83 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:48635
P
tcpdump-4.5.1-10.1 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:71024
P
libsndfile-devel-1.0.28-3.24 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:69779
P
Security update for openvswitch (Important)
2021-02-11
oval:org.opensuse.security:def:71622
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:107227
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:116785
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:61881
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:100561
P
libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:64296
P
libX11-6 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:67730
P
libsndfile-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:49233
P
libsndfile-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:66436
P
libXdmcp-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:73219
P
libsndfile-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:64383
P
libsndfile-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:67630
P
jq on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:73101
P
gstreamer-plugins-base on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:49179
P
libjavascriptcoregtk-4_0-18 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:66528
P
libsndfile-devel on GA media (Moderate)
2020-12-01
oval:com.ubuntu.bionic:def:2017125620000000
V
CVE-2017-12562 on Ubuntu 18.04 LTS (bionic) - low.
2017-08-05
oval:com.ubuntu.artful:def:201712562000
V
CVE-2017-12562 on Ubuntu 17.10 (artful) - low.
2017-08-05
oval:com.ubuntu.xenial:def:201712562000
V
CVE-2017-12562 on Ubuntu 16.04 LTS (xenial) - low.
2017-08-05
oval:com.ubuntu.xenial:def:2017125620000000
V
CVE-2017-12562 on Ubuntu 16.04 LTS (xenial) - low.
2017-08-05
oval:com.ubuntu.bionic:def:201712562000
V
CVE-2017-12562 on Ubuntu 18.04 LTS (bionic) - low.
2017-08-05
oval:com.ubuntu.disco:def:2017125620000000
V
CVE-2017-12562 on Ubuntu 19.04 (disco) - low.
2017-08-05
oval:com.ubuntu.cosmic:def:201712562000
V
CVE-2017-12562 on Ubuntu 18.10 (cosmic) - low.
2017-08-05
oval:com.ubuntu.cosmic:def:2017125620000000
V
CVE-2017-12562 on Ubuntu 18.10 (cosmic) - low.
2017-08-05
oval:com.ubuntu.trusty:def:201712562000
V
CVE-2017-12562 on Ubuntu 14.04 LTS (trusty) - low.
2017-08-05
BACK