CVE-2018-17095: Buffer Overflow
An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17095?
CVE-2018-17095 is rated as a high severity vulnerability due to the potential for a heap-based buffer overflow.
How do I fix CVE-2018-17095?
To mitigate CVE-2018-17095, users should upgrade to a patched version of the Audio File Library, such as 0.3.6-5 or later.
Which versions of the Audio File Library are affected by CVE-2018-17095?
CVE-2018-17095 affects Audio File Library versions 0.3.0 through 0.3.6.
What system can be impacted by CVE-2018-17095?
CVE-2018-17095 can impact systems running affected versions of the Audio File Library on platforms such as Debian and Ubuntu.
What functionality is compromised by CVE-2018-17095?
CVE-2018-17095 compromises the functionality of the sfconvert command, leading to potential crashes or arbitrary code execution.