Vulnerability Name:

CVE-2017-7697 (CCN-124496)

Assigned:2017-04-11
Published:2017-04-11
Updated:2022-04-18
Summary:In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-125
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-7697

Source: BID
Type: Broken Link
97587

Source: CCN
Type: BID-97587
libsamplerate 'src_sinc.c' Local Buffer Overflow Vulnerability

Source: XF
Type: UNKNOWN
libsamplerate-cve20177697-bo(124496)

Source: CCN
Type: libsamplerate GIT Repository
libsamplerate

Source: CONFIRM
Type: Issue Tracking, Patch
https://github.com/erikd/libsamplerate/issues/11

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20211214 [SECURITY] [DLA 2845-1] libsamplerate security update

Vulnerable Configuration:Configuration 1:
  • cpe:/a:libsamplerate_project:libsamplerate:*:*:*:*:*:*:*:* (Version <= 0.1.8)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20177697
    V
    CVE-2017-7697
    2022-09-02
    oval:org.opensuse.security:def:31372
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:34053
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:30163
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:34611
    P
    Security update for bcm43xx-firmware (Important)
    2021-12-13
    oval:org.opensuse.security:def:34610
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:31312
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:33738
    P
    Security update for pcre (Moderate)
    2021-11-10
    oval:org.opensuse.security:def:34571
    P
    Security update for git (Low)
    2021-10-20
    oval:org.opensuse.security:def:33988
    P
    Security update for strongswan (Important)
    2021-10-19
    oval:org.opensuse.security:def:33727
    P
    Security update for curl (Moderate)
    2021-10-12
    oval:org.opensuse.security:def:33726
    P
    Security update for apache2 (Important)
    2021-10-06
    oval:org.opensuse.security:def:34527
    P
    Security update for apache2 (Important)
    2021-09-02
    oval:org.opensuse.security:def:31263
    P
    Security update for libesmtp (Important)
    2021-09-02
    oval:org.opensuse.security:def:32982
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:33957
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:34502
    P
    Security update for the Linux Kernel (Important)
    2021-08-10
    oval:org.opensuse.security:def:31207
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-06-18
    oval:org.opensuse.security:def:34463
    P
    Security update for libjpeg-turbo (Moderate)
    2021-06-11
    oval:org.opensuse.security:def:31197
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:36144
    P
    gtk2-2.18.9-0.23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36103
    P
    cron-4.1-194.211.213.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:30077
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:32092
    P
    Security update for the Linux Kernel (Important)
    2021-05-18
    oval:org.opensuse.security:def:31160
    P
    Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP3) (Important)
    2021-04-28
    oval:org.opensuse.security:def:34414
    P
    Security update for java-11-openjdk (Important)
    2021-04-26
    oval:org.opensuse.security:def:32895
    P
    Security update for cifs-utils (Moderate)
    2021-04-13
    oval:org.opensuse.security:def:28946
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:31351
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:34027
    P
    Security update for krb5-appl (Important)
    2021-02-19
    oval:org.opensuse.security:def:30020
    P
    Security update for python (Important)
    2021-02-11
    oval:org.opensuse.security:def:34622
    P
    Security update for python36 (Important)
    2021-02-10
    oval:org.opensuse.security:def:35247
    P
    Security update for the Linux Kernel (Important)
    2021-01-15
    oval:org.opensuse.security:def:35249
    P
    Security update for gimp (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:32838
    P
    Security update for openexr (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:28862
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:29301
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:30601
    P
    Security update for puppet
    2020-12-01
    oval:org.opensuse.security:def:27113
    P
    ecryptfs-utils-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33244
    P
    python-pam on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29975
    P
    Security update for libsamplerate (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30600
    P
    Security update for PostgreSQL
    2020-12-01
    oval:org.opensuse.security:def:27056
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33195
    P
    libxslt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29939
    P
    Security update for libksba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26975
    P
    libtiff3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33138
    P
    libapr-util1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26847
    P
    yast2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29257
    P
    Security update for tomcat6 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26783
    P
    mipv6d on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29240
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:26772
    P
    libvorbis on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29201
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:35209
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26771
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32744
    P
    logwatch on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29152
    P
    Security update for libssh2_org (Important)
    2020-12-01
    oval:org.opensuse.security:def:32609
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29098
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:32531
    P
    ipsec-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32520
    P
    glib2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32519
    P
    ghostscript-fonts-other on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28805
    P
    Security update for orca (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28720
    P
    Security update for kdelibs4
    2020-12-01
    oval:org.opensuse.security:def:34356
    P
    Security update for syslog-ng (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30522
    P
    Security update for hplip
    2020-12-01
    oval:org.opensuse.security:def:28589
    P
    Security update for mozilla-nspr, mozilla-nss
    2020-12-01
    oval:org.opensuse.security:def:34199
    P
    Security update for perf
    2020-12-01
    oval:org.opensuse.security:def:30478
    P
    Security update for bind (Critical)
    2020-12-01
    oval:org.opensuse.security:def:28521
    P
    Security update for openvpn-openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34110
    P
    Security update for mutt (Important)
    2020-12-01
    oval:org.opensuse.security:def:30459
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:28510
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:30420
    P
    Security update for xorg-x11-libXpm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28509
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:30371
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35465
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:33821
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:30316
    P
    Security update for tgt
    2020-12-01
    oval:org.opensuse.security:def:35421
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:35394
    P
    Security update for OpenSLP
    2020-12-01
    oval:org.opensuse.security:def:35355
    P
    security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35306
    P
    Security update for log4j (Important)
    2020-12-01
    oval:org.opensuse.security:def:32054
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29933
    P
    Security update for libgssglue
    2020-12-01
    oval:org.opensuse.security:def:31416
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:29801
    P
    Security update for icu (Important)
    2020-12-01
    oval:org.opensuse.security:def:35088
    P
    Security update for kdebase4-workspace
    2020-12-01
    oval:org.opensuse.security:def:29728
    P
    Security update for MozillaFirefox, firefox-glib2, firefox-gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:34998
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:29717
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:34941
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:28220
    P
    Security update for libsamplerate (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29716
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:34842
    P
    Security update for bind (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28185
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34706
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:27547
    P
    python-lxml on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31052
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27503
    P
    libwsman-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30965
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27489
    P
    libsss_idmap-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30908
    P
    Security update for freetype2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27450
    P
    libgpgme-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30818
    P
    Security update for cpio (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27401
    P
    flac-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33350
    P
    Security update for openssh-openssl1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30686
    P
    Security update for LibVNCServer (Critical)
    2020-12-01
    oval:org.opensuse.security:def:27348
    P
    libsnmp15-openssl1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33306
    P
    yast2-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30612
    P
    Security update for strongswan
    2020-12-01
    oval:org.opensuse.security:def:27197
    P
    libmusicbrainz4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33283
    P
    w3m on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.cosmic:def:201776970000000
    V
    CVE-2017-7697 on Ubuntu 18.10 (cosmic) - low.
    2017-04-11
    oval:com.ubuntu.artful:def:20177697000
    V
    CVE-2017-7697 on Ubuntu 17.10 (artful) - low.
    2017-04-11
    oval:com.ubuntu.trusty:def:20177697000
    V
    CVE-2017-7697 on Ubuntu 14.04 LTS (trusty) - low.
    2017-04-11
    oval:com.ubuntu.bionic:def:201776970000000
    V
    CVE-2017-7697 on Ubuntu 18.04 LTS (bionic) - low.
    2017-04-11
    oval:com.ubuntu.bionic:def:20177697000
    V
    CVE-2017-7697 on Ubuntu 18.04 LTS (bionic) - low.
    2017-04-11
    oval:com.ubuntu.xenial:def:20177697000
    V
    CVE-2017-7697 on Ubuntu 16.04 LTS (xenial) - low.
    2017-04-11
    oval:com.ubuntu.xenial:def:201776970000000
    V
    CVE-2017-7697 on Ubuntu 16.04 LTS (xenial) - low.
    2017-04-11
    oval:com.ubuntu.cosmic:def:20177697000
    V
    CVE-2017-7697 on Ubuntu 18.10 (cosmic) - low.
    2017-04-11
    oval:com.ubuntu.disco:def:201776970000000
    V
    CVE-2017-7697 on Ubuntu 19.04 (disco) - low.
    2017-04-11
    oval:com.ubuntu.precise:def:20177697000
    V
    CVE-2017-7697 on Ubuntu 12.04 LTS (precise) - low.
    2017-04-11
    BACK
    libsamplerate_project libsamplerate *
    debian debian linux 9.0