6.8
CVSSv2

CVE-2018-17095

Published: 16/09/2018 Updated: 09/02/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

audio file library project audio file library 0.3.0

audio file library project audio file library 0.3.1

audio file library project audio file library 0.3.2

audio file library project audio file library 0.3.3

audio file library project audio file library 0.3.4

audio file library project audio file library 0.3.5

audio file library project audio file library 0.3.6

canonical ubuntu linux 14.04

Vendor Advisories

Synopsis Moderate: audiofile security update Type/Severity Security Advisory: Moderate Topic An update for audiofile is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score ...
Several security issues were fixed in audiofile ...
Debian Bug report logs - #913166 CVE-2018-17095 Package: src:audiofile; Maintainer for src:audiofile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 7 Nov 2018 18:57:02 UTC Severity: important Tags: security, upstream Found in versio ...
Debian Bug report logs - #903499 audiofile: CVE-2018-13440 Package: src:audiofile; Maintainer for src:audiofile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 10 Jul 2018 19:12:02 UTC Severity: important Tags: security, upstream ...
The audiofile Audio File Library 036 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleStatecpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert (CVE-2018-13440) An issue has been discovered in mpruett Audio File Library (aka audiofile) 036 A heap-based buffer ...
An issue has been discovered in mpruett Audio File Library (aka audiofile) 036 A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert ...