The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be prepared to handle a wide variety of exceptions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-03-01T05:00:00
Updated: 2024-08-05T21:13:49.208Z
Reserved: 2018-02-28T00:00:00
Link: CVE-2017-18207
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-03-01T05:29:00.227
Modified: 2024-11-21T03:19:34.033
Link: CVE-2017-18207
Redhat
No data.