CVE-2017-6892: Libsndfile Project Libsndfile
High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.
In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.
Affected products
- Libsndfile Project Libsndfile: version 1.0.28 only
Published 2017-06-12. Last modified 2026-06-17.