MEDIUM
libsndfile: OOB read in sf_write_int in sndfile.c
Published Nov 22, 2018
6.5
MEDIUMCVSS 3.0
EPSS 2.96%
Description
An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.
Affected products
No data.
Configuration 1
- 1.0.28
Configuration 2
- 8.0
No data.
Red Hat Enterprise Linux 6
libsndfile
Not affected
Red Hat Enterprise Linux 7
libsndfile
Fix deferred
Red Hat Enterprise Linux 8
libsndfile
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | libsndfile | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libsndfile | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | libsndfile | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of libsndfile as shipped with Red Hat Enterprise Linux 6. This issue affects the versions of libsndfile as shipped with Red Hat Enterprise Linux 7.
Weaknesses (2)
References (9)
- http://www.securityfocus.com/bid/105996 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-19432 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1652566 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-11123 Advisory
- https://github.com/erikd/libsndfile/issues/427 x_refsource_MISCExploitPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/12/msg00016.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-19432
- https://usn.ubuntu.com/4013-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2018-19432
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/105996 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-19432 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1652566 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-11123 | Advisory | |
| https://github.com/erikd/libsndfile/issues/427 | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2018/12/msg00016.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-19432 | ||
| https://usn.ubuntu.com/4013-1/ | vendor-advisoryx_refsource_UBUNTU | |
| https://www.cve.org/CVERecord?id=CVE-2018-19432 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 22, 2018
Updated Aug 5, 2024
Reserved Nov 21, 2018
Link CVE-2018-19432
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-11123 Assigner mitre
Published Nov 22, 2018
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2018-11123