CVE-2018-19758: Medium severity Libsndfile Project Libsndfile vulnerability
Published Nov 30, 2018
·Updated
Last updated 25 August 2025
Other sources
There is a heap-based buffer over-read at wav.c in wavwriteheader in libsndfile 1.0.28 that will cause a denial of service.
— Launchpad
Affected Software
3 affected componentsFixes available
Libsndfile Project Libsndfile=1.0.28
Debian Debian Linux=8.0
debian/libsndfile
1.0.31-21.0.31-2+deb11u21.2.0-1+deb12u11.2.2-21.2.2-4
Remediation
Event History
Nov 30, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:58 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:57 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:58 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-19758?
CVE-2018-19758 has been classified as a denial of service vulnerability.
2
How do I fix CVE-2018-19758?
To remediate CVE-2018-19758, you should upgrade to libsndfile versions 1.0.31-2, 1.2.0-1, 1.2.2-1, or 1.2.2-2.
3
Which version of libsndfile is affected by CVE-2018-19758?
CVE-2018-19758 specifically affects libsndfile version 1.0.28.
4
What type of vulnerability is CVE-2018-19758?
CVE-2018-19758 is a heap-based buffer over-read vulnerability.
5
On which operating system does CVE-2018-19758 affect libsndfile?
CVE-2018-19758 affects libsndfile on Debian GNU/Linux version 8.0.