Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-11548

30
FAUCET Score

CVE-2017-11548 describes a denial-of-service vulnerability in Xiph.Org libao 1.2.0, specifically within the _tokenize_matrix function in audio_out.c. A remote attacker can trigger memory corruption by providing a specially crafted MP3 file to a system using the affected libao version. This vulnerability is rated Medium severity (CVSS 5.5) with a local attack vector requiring user interaction, leading to a high impact on availability. There is no impact on confidentiality or integrity. While not listed on the CISA KEV catalog or actively exploited, an exploit (EDB-42400) is publicly available on ExploitDB. The CVE has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.2.0CPE matchmatch criteria
cpe:2.3:a:xiph:libao:1.2.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.85%
Probability of exploitation in next 30 days
EPSS Percentile
89.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-42400 · Jul 31, 2017
This CVE's current EPSS score of 0.0386 is in the 96th percentile among its peer group of 5,758 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

microsoftpatch availablevia msrc
Product: 16890-16823Fixed in: 1.2.0-24
microsoftpatch availablevia msrc
Product: cbl2 libao 1.2.0-24 on CBL Mariner 2.0Fixed in: 1.2.0-24
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: libao
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: libao
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: libao

Vendor Advisories (2)

redhatCVE-2017-11548Low

libao: Invalid memory allocation in _tokenize_matrix function in audio_out.c

Aug 7, 2017
microsoft2017-Jul/CVE-2017-11548Moderate

The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service

Jul 11, 2017

References

seclists.org / fulldisclosure/2017/Jul/84
Mailing ListThird Party Advisory
exploit-db.com / exploits/42400
Third Party AdvisoryVDB Entry