First published: Sun Sep 16 2018(Updated: )
An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/audiofile | 0.3.6-5 0.3.6-7 | |
Audio File Library | =0.3.0 | |
Audio File Library | =0.3.1 | |
Audio File Library | =0.3.2 | |
Audio File Library | =0.3.3 | |
Audio File Library | =0.3.4 | |
Audio File Library | =0.3.5 | |
Audio File Library | =0.3.6 | |
Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17095 is rated as a high severity vulnerability due to the potential for a heap-based buffer overflow.
To mitigate CVE-2018-17095, users should upgrade to a patched version of the Audio File Library, such as 0.3.6-5 or later.
CVE-2018-17095 affects Audio File Library versions 0.3.0 through 0.3.6.
CVE-2018-17095 can impact systems running affected versions of the Audio File Library on platforms such as Debian and Ubuntu.
CVE-2018-17095 compromises the functionality of the sfconvert command, leading to potential crashes or arbitrary code execution.