已开启
CVE-2017-6834 #24
Funda Wang创建于  5月12日
Funda Wang
Funda Wang
5月12日 创建

一、漏洞信息
漏洞编号:CVE-2017-6834
漏洞归属组件:audiofile
漏洞归属的版本:0.3.6
CVSS评分:
BaseScore:5.5 Medium
Vector:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
漏洞简述:
Heap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
漏洞公开时间:2017-03-21 00:59
漏洞创建时间:2026-05-12 23:38:56
漏洞详情参考链接:
https://nvd.nist.gov/vuln/detail/CVE-2017-6834

更多参考(点击展开)
参考来源 参考链接 来源链接
MISC https://github.com/mpruett/audiofile/pull/42
MISC https://github.com/mpruett/audiofile/issues/38
MISC https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-ulaw2linear_buf-g711-cpp/
MLIST http://www.openwall.com/lists/oss-security/2017/03/13/6
DEBIAN http://www.debian.org/security/2017/dsa-3814
redhat https://access.redhat.com/security/cve/CVE-2017-6834

漏洞分析指导链接:
https://atomgit.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md
漏洞数据来源:
openBrain开源漏洞感知系统
漏洞补丁信息:

详情(点击展开)

二、漏洞分析结构反馈
影响性分析说明:

openEuler评分:

受影响版本排查(受影响/不受影响):
1.master(0.3.6):
2.openEuler-20.03-LTS-SP4(0.3.6):
3.openEuler-22.03-LTS-SP4(0.3.6):
4.openEuler-24.03-LTS(0.3.6):
5.openEuler-24.03-LTS-Next(0.3.6):
6.openEuler-24.03-LTS-SP1(0.3.6):
7.openEuler-24.03-LTS-SP3(0.3.6):
8.openEuler-24.03-LTS-SP4(0.3.6):

修复是否涉及abi变化(是/否):
1.master(0.3.6):
2.openEuler-20.03-LTS-SP4(0.3.6):
3.openEuler-22.03-LTS-SP4(0.3.6):
4.openEuler-24.03-LTS(0.3.6):
5.openEuler-24.03-LTS-Next(0.3.6):
6.openEuler-24.03-LTS-SP1(0.3.6):
7.openEuler-24.03-LTS-SP3(0.3.6):
8.openEuler-24.03-LTS-SP4(0.3.6):

原因说明:
1.master(0.3.6):
2.openEuler-20.03-LTS-SP4(0.3.6):
3.openEuler-22.03-LTS-SP4(0.3.6):
4.openEuler-24.03-LTS(0.3.6):
5.openEuler-24.03-LTS-Next(0.3.6):
6.openEuler-24.03-LTS-SP1(0.3.6):
7.openEuler-24.03-LTS-SP3(0.3.6):
8.openEuler-24.03-LTS-SP4(0.3.6):

likedislike
openeuler-ci-botopeneuler-ci-bot成员
5月12日 添加了label:sig/Base-service
openeuler-ci-bot
openeuler-ci-bot成员
5月12日 评论:

Welcome To openEuler Community

Hey @fundawang , thanks for your contribution to the community.

Bot Usage Manual

I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands.

Contact Guide

If you have any questions, please contact the SIG: Base-service ,
and any of the maintainers: @dillon_chen, @licihua, @overweight, @shenyangyang, @zhujianwei001 ,
and any of the committers: @dillon_chen .

likedislike
yangwei999
5月14日 评论:

/get-cve

likedislike
openeuler-ci-bot
openeuler-ci-bot成员
5月14日 评论:

@yangwei999 CVE信息从NVD同步成功, 稍后请重新加载页面.

likedislike
openeuler-ci-botopeneuler-ci-bot成员
5月14日 修改了issue 的描述
openeuler-ci-botopeneuler-ci-bot成员
5月14日 将 dillon_chen 设为负责人
openeuler-ci-botopeneuler-ci-bot成员
5月14日 添加了label:CVE/UNFIXED
Iinfra_team
5月18日 关联了pull request:fix(cve): 修复 CVE-2017-6834 在 audiofile 中的漏洞