Divide-By-Zero Vulnerability in GNU Libextractor by GNU
CVE-2017-15266
5.5MEDIUM
Summary
In version 1.4 of GNU Libextractor, a Divide-By-Zero vulnerability exists in the EXTRACTOR_wav_extract_method function, located in wav_extractor.c. This vulnerability can be triggered by providing a zero sample rate, which may lead to unexpected behavior in applications using the library. It is crucial for developers and system administrators to review and apply the appropriate security updates to mitigate potential exploitation risks.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved