CVE-2017-14634 describes a divide-by-zero error in the double64_init() function of libsndfile 1.0.28, affecting Debian and libsndfile projects. This vulnerability carries a CVSSv3 score of 6.5 (Medium), indicating it can be triggered remotely with low attack complexity, requiring user interaction (playing a crafted audio file) to cause a denial of service. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or ExploitDB. Community discussion is minimal, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.28CPE matchmatch criteria | cpe:2.3:a:libsndfile_project:libsndfile:1.0.28:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2017-14634
Jan 12, 2021libsndfile: Divide-by-zero in the double64_init() function
Sep 14, 2017In libsndfile 1.0.28 a divide-by-zero error exists in the function double64_init() in double64.c which may lead to DoS when playing a crafted audio file.
Sep 12, 2017