CVE Vulnerabilities

CVE-2017-17555

NULL Pointer Dereference

Published: Dec 12, 2017 | Modified: Apr 20, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Aubio Aubio 0.4.6 (including) 0.4.6 (including)
Ffmpeg Ffmpeg 3.4.1 (including) 3.4.1 (including)
Aubio Ubuntu artful *
Aubio Ubuntu bionic *
Aubio Ubuntu cosmic *
Aubio Ubuntu esm-apps/bionic *
Aubio Ubuntu esm-apps/xenial *
Aubio Ubuntu trusty *
Aubio Ubuntu upstream *
Aubio Ubuntu xenial *
Aubio Ubuntu zesty *

Potential Mitigations

References