CVE-2018-19662: High severity Libsndfile Project Libsndfile vulnerability
Published Nov 29, 2018
·Updated
An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alawarray in alaw.c that will lead to a denial of service.
Affected Software
3 affected componentsFixes available
Libsndfile Project Libsndfile=1.0.28
Debian Debian Linux=8.0
debian/libsndfile
1.0.31-21.0.31-2+deb11u21.2.0-1+deb12u11.2.2-21.2.2-4
Remediation
Patch Available
Event History
Nov 29, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:57 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:57 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:58 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-19662?
CVE-2018-19662 has been classified as a denial of service vulnerability due to buffer over-read.
2
How do I fix CVE-2018-19662?
To fix CVE-2018-19662, update libsndfile to version 1.0.31-2, 1.2.0-1, 1.2.2-1, or 1.2.2-2.
3
What software is affected by CVE-2018-19662?
CVE-2018-19662 affects libsndfile version 1.0.28.
4
What causes the vulnerability in CVE-2018-19662?
CVE-2018-19662 is caused by a buffer over-read in the function i2alaw_array in alaw.c.
5
Is CVE-2018-19662 specific to any operating system?
CVE-2018-19662 specifically impacts Debian GNU/Linux version 8.0 and the libsndfile software.