← Vulnerability feed

Vulnerability record · CVE-2017-12950 · published 28 August 2017

CVE-2017-12950: Linuxsampler libgig null pointer dereference vulnerability

Linuxsampler · Libgig

The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

6.5 CVSS 3.1 Medium EPSS 5.1% · top 8.0% CWE-476 · NULL pointer dereference
6.5CVSS 3.1 base score, v2 4.3
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2017/Aug/39 Mailing ListThird Party Advisory
https://www.exploit-db.com/exploits/42546/ Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2017/Aug/39 Mailing ListThird Party Advisory
https://www.exploit-db.com/exploits/42546/ Third Party AdvisoryVDB Entry

Track CVE-2017-12950 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-18197Linuxsampler libgig memory buffer overflow vulnerabilityAn issue was discovered in libgig 4.1.0. There is an operator new[] failure (due to a big pSampleLoops heap request) in DLS::Sampler::Sampler in DLS.…EPSS 1.4%8.8CVE-2021-32294Linuxsampler libgig out-of-bounds write vulnerabilityAn issue was discovered in libgig through 20200507. A heap-buffer-overflow exists in the function RIFF::List::GetSubList located in RIFF.cpp. It allo…EPSS 1.5%8.8CVE-2018-18193Linuxsampler libgig memory buffer overflow vulnerabilityAn issue was discovered in libgig 4.1.0. There is operator new[] failure (due to a big pWavePoolTable heap request) in DLS::File::File in DLS.cpp.EPSS 1.2%8.8CVE-2018-18194Linuxsampler libgig out-of-bounds read vulnerabilityAn issue was discovered in libgig 4.1.0. There is a heap-based buffer over-read in DLS::Region::GetSample() in DLS.cpp.EPSS 1.2%8.8CVE-2018-18196Linuxsampler libgig out-of-bounds read vulnerabilityAn issue was discovered in libgig 4.1.0. There is a heap-based buffer over-read in RIFF::List::GetListTypeString in RIFF.cpp.EPSS 1.2%8.8CVE-2018-14449Linuxsampler libgig out-of-bounds read vulnerabilityAn issue was discovered in libgig 4.1.0. There is an out of bounds read in gig::File::UpdateChunks in gig.cpp.EPSS 1.2%8.8CVE-2018-14450Linuxsampler libgig out-of-bounds read vulnerabilityAn issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the "update dimension region's chunks" feature of the function gig::Region…EPSS 1.2%8.8CVE-2018-14451Linuxsampler libgig out-of-bounds write vulnerabilityAn issue was discovered in libgig 4.1.0. There is a heap-based buffer overflow in the function RIFF::Chunk::Read in RIFF.cpp.EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2017-12950), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.