VDB

CVE-2017-18207

CVE-2017-18207 PUBLISHED

The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be prepared to handle a wide variety of exceptions.

EPSS 0.47% · 65.2th percentile

Risk Scores

EPSS Score
0.47%
65.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSpython2.72.7.12-1ubuntu0~16.04.18+esm4, 2.7.12-1ubuntu0~16.04.18+esm1, 2.7.12-1ubuntu0~16.04.16
Ubuntu:Pro:14.04:LTSpython3.5*, 3.5.2-2ubuntu0~16.04.4~14.04.1+esm7, 3.5.2-2ubuntu0~16.04.4~14.04.1+esm6
Ubuntu:Pro:18.04:LTSpython3.6*, 3.6.3-1ubuntu1, 3.6.4~rc1-2
Ubuntu:Pro:18.04:LTSpython3.73.7.5-2ubuntu1~18.04.2+esm8, *, *
Ubuntu:22.04:LTSpython2.72.7.18-13ubuntu1, 2.7.18-13, 2.7.18-8build1
Ubuntu:Pro:14.04:LTSpython3.4*, *, *
Ubuntu:Pro:18.04:LTSpython2.7*, *, *
Ubuntu:Pro:16.04:LTSpython3.5*, 0, 3.5.0-3ubuntu1
Ubuntu:Pro:14.04:LTSpython2.72.7.5-8ubuntu3, 2.7.6-2, *
Ubuntu:Pro:20.04:LTSpython2.72.7.17~rc1-1, 2.7.17-1, 2.7.17-1ubuntu5

Timeline

  • Mar 1, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • May 13, 2022 CVE Updated
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›