CVE-2018-17095

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
16/09/2018
Last modified:
13/08/2025

Description

An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:audiofile:audiofile:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.3:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.4:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.5:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.6:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*