-
Notifications
You must be signed in to change notification settings - Fork 172
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
global buffer overflow in calc_output_single (src_sinc.c) #11
Comments
This is fixed in version 1.0.9 which was released in September last year. Ok to close? |
Looks like the release was a little messed up, but it is definitely available here: http://www.mega-nerd.com/libsamplerate/download.html |
this seems not reproducible in the latest release. Was this bug reported in another way/place or it is not reproducible because of a change of code? |
I'm pretty sure I found and fixed this on my own in the lead up to the 1.0.9 release. I spent a lot of CPU hours running AFL across all my C projects. |
ok, thanks. I will inform the community to update to 1.0.9 or patch because of this bug. |
this is CVE-2017-7697 |
On 0.1.8:
Reproducer:
https://github.com/asarubbo/poc/blob/master/00262-libsamplerate-globaloverflow-calc_output_single
The text was updated successfully, but these errors were encountered: