PT-2018-13891 · Mpruett+6 · Audiofile+6

Published

2018-09-16

·

Updated

2026-05-15

·

CVE-2018-17095

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mpruett Audio File Library (aka audiofile) versions 0.3.0 through 0.3.6
Description A heap-based buffer overflow issue has been found in the Expand3To4Module::run function when running sfconvert, potentially leading to exploitation.
Recommendations For versions 0.3.0 through 0.3.6, consider disabling the Expand3To4Module::run function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2193
ALT-PU-2022-3089
AZL-45405
AZL-66252
CESA-2020_3877
CVE-2018-17095
MGASA-2018-0441
OESA-2026-2353
OPENSUSE-SU-2018_3537-1
OPENSUSE-SU-2018_3694-1
OPENSUSE-SU-2024:10640-1
RHSA-2020:3877
RHSA-2020_3877
SUSE-SU-2018:3506-1
SUSE-SU-2018:3588-1
SUSE-SU-2018:3588-2
SUSE-SU-2018_3506-1
SUSE-SU-2018_3588-1
SUSE-SU-2018_3588-2
USN-3800-1
USN-6558-1

Affected Products

Alt Linux
Centos
Linuxmint
Red Hat
Suse
Ubuntu
Audiofile