openwrt ▾
›
master ▾
›
vulnerability
›
CVE-2017-11548
Component Overview
Vulnerability Overview
Name
CVE-2017-11548
Source
NVD (
link
)
Debian (
link
)
Description
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file.
CWEs
CWE-119
Published Date
Jul 31, 2017
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://seclists.org/fulldisclosure/2017/Jul/84
Mailing List
https://www.exploit-db.com/exploits/42400/
VDB Entry
http://seclists.org/fulldisclosure/2017/Jul/84
Mailing List
https://www.exploit-db.com/exploits/42400/
VDB Entry
Analysis
#
Affected Component
Analysis
libao
Patched
Vulnerability Ratings
#
5.5
CVSSv31
4.3
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
libao
buildroot
2025.02.x
1.2.0
Exploitable
libao
buildroot
master
1.2.2
Not Affected
libao
openwrt
openwrt-25.12
1.2.0-r2
Patched
libao
yocto
kirkstone
1.2.0
Not Affected
libao
yocto
master
1.2.0
Not Affected
libao
yocto
scarthgap
1.2.0
Not Affected
Resolved with patches
#
libao (openwrt:master)
#
Title
Author
Resolve
1
Check memory allocations for success
Ron <ron@debian.org>
CVE-2017-11548
libao (openwrt:openwrt-25.12)
#
Title
Author
Resolve
1
Check memory allocations for success
Ron <ron@debian.org>
CVE-2017-11548