VDB

CVE-2017-18207

CVE-2017-18207 PUBLISHED CVSS 6.5 MEDIUM

The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be prepared to handle a wide variety of exceptions.

EPSS 1.32% · 69.8th percentile

Risk Scores

CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
1.32%
69.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSpython2.72.7.12-1ubuntu0~16.04.18+esm4, 2.7.12-1ubuntu0~16.04.18+esm1, 2.7.12-1ubuntu0~16.04.16
Ubuntu:Pro:14.04:LTSpython3.5*, 3.5.2-2ubuntu0~16.04.4~14.04.1+esm7, 3.5.2-2ubuntu0~16.04.4~14.04.1+esm6
Ubuntu:Pro:18.04:LTSpython3.6*, 3.6.3-1ubuntu1, 3.6.4~rc1-2
Ubuntu:Pro:18.04:LTSpython3.73.7.5-2ubuntu1~18.04.2+esm8, *, *
Ubuntu:22.04:LTSpython2.72.7.18-13ubuntu1, 2.7.18-13, 2.7.18-8build1
Ubuntu:Pro:14.04:LTSpython3.4*, *, *
Ubuntu:Pro:18.04:LTSpython2.7*, *, *
Ubuntu:Pro:16.04:LTSpython3.5*, 0, 3.5.0-3ubuntu1
Ubuntu:Pro:14.04:LTSpython2.72.7.5-8ubuntu3, 2.7.6-2, *
Ubuntu:Pro:20.04:LTSpython2.72.7.17~rc1-1, 2.7.17-1, 2.7.17-1ubuntu5

Timeline

  • Mar 1, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Oct 27, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Mar 3, 2022 EPSS Score
  • May 5, 2022 EPSS Score
  • Jul 7, 2022 EPSS Score
  • Nov 11, 2022 EPSS Score
  • Jan 13, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›