CVE-2017-18207 PUBLISHED

The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be prepared to handle a wide variety of exceptions.

EPSS 0.57% · 68.4th percentile

Risk Scores

EPSS Score
0.57%
68.4th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSpython2.72.7.12-1ubuntu0~16.04.18+esm17, 2.7.11-6, 2.7.11-4
Ubuntu:Pro:14.04:LTSpython3.53.5.2-2ubuntu0~16.04.4~14.04.1+esm3, 3.5.2-2ubuntu0~16.04.4~14.04.1+esm1, 3.5.2-2ubuntu0~16.04.4~14.04.1
Ubuntu:Pro:18.04:LTSpython3.63.6.3-1ubuntu1, 3.6.9-1~18.04ubuntu1.13+esm8, 3.6.9-1~18.04ubuntu1.13+esm7
Ubuntu:Pro:18.04:LTSpython3.73.7.5-2ubuntu1~18.04.2+esm7, 3.7.5-2ubuntu1~18.04.2+esm9, 3.7.5-2ubuntu1~18.04.2+esm8
Ubuntu:22.04:LTSpython2.72.7.18-13ubuntu1.2, 0, 2.7.18-8build1
Ubuntu:Pro:14.04:LTSpython3.43.4~b2-1, 3.4~b1-5ubuntu2, 3.4~b1-4ubuntu6
Ubuntu:Pro:18.04:LTSpython2.72.7.17-1~18.04ubuntu1.8, 0, 2.7.14-2ubuntu2
Ubuntu:Pro:16.04:LTSpython3.50, 3.5.2-2ubuntu0~16.04.13+esm17, 3.5.2-2ubuntu0~16.04.13+esm21
Ubuntu:Pro:14.04:LTSpython2.70, 2.7.6-5, 2.7.6-4ubuntu1
Ubuntu:Pro:20.04:LTSpython2.70, 2.7.18-1~20.04.7+esm8, 2.7.18-1~20.04.7+esm7

Timeline

References

Open in Interactive Console →