The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be prepared to handle a wide variety of exceptions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-03-01T05:00:00

Updated: 2024-08-05T21:13:49.208Z

Reserved: 2018-02-28T00:00:00

Link: CVE-2017-18207

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-01T05:29:00.227

Modified: 2024-08-05T22:15:21.810

Link: CVE-2017-18207

cve-icon Redhat

No data.