USN-6558-1: audiofile vulnerabilities
It was discovered that audiofile could be made to dereference invalid memory. If a user or an automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-13440) It was discovered that audiofile could be made to write out of bounds. If a user or an automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-17095) It was discovered that audiofile could be made to dereference invalid memory. If a user or an automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. (CVE-2019-13147) It was discovered that audiofile could be made to leak memory. If a user or an automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to obtain sensitive information. (CVE-2022-24599)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6558-1?
USN-6558-1 is classified as a potential denial of service vulnerability.
How do I fix USN-6558-1?
To fix USN-6558-1, update to the latest version of audiofile-tools or libaudiofile1 as specified in the advisory.
Which Ubuntu versions are affected by USN-6558-1?
USN-6558-1 affects Ubuntu 16.04, 18.04, 20.04, 22.04, 23.04, and 23.10.
What are the packages impacted by USN-6558-1?
The packages impacted by USN-6558-1 include audiofile-tools and libaudiofile1.
What is the exploit potential of USN-6558-1?
Exploitation of USN-6558-1 can lead to a denial of service condition if a specially crafted file is opened.