cbcvebase.
CVE-2018-17095
published 2018-09-16

CVE-2018-17095: An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in…

PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
4.65%
90.7th percentile
An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

Affected

19 ranges
VendorProductVersion rangeFixed in
audiofileaudiofile
audiofileaudiofile
audiofileaudiofile
audiofileaudiofile
audiofileaudiofile
audiofileaudiofile
audiofileaudiofile
audiofileaudiofile>= 0 < 0.3.6-50.3.6-5
audiofileaudiofile>= 0 < 0.3.6-50.3.6-5
audiofileaudiofile>= 0 < 0.3.6-50.3.6-5
audiofileaudiofile>= 0 < 0.3.6-50.3.6-5
audiofileaudiofile>= 0 < 0.3.6-2ubuntu0.14.04.30.3.6-2ubuntu0.14.04.3
audiofileaudiofile>= 0 < 0.3.6-5+deb10u1build0.20.04.10.3.6-5+deb10u1build0.20.04.1
audiofileaudiofile>= 0 < 0.3.6-5+deb10u1build0.22.04.10.3.6-5+deb10u1build0.22.04.1
audiofileaudiofile>= 0 < 0.3.6-2ubuntu0.14.04.3+esm10.3.6-2ubuntu0.14.04.3+esm1
audiofileaudiofile>= 0 < 0.3.6-2ubuntu0.16.04.1+esm10.3.6-2ubuntu0.16.04.1+esm1
audiofileaudiofile>= 0 < 0.3.6-4ubuntu0.1~esm10.3.6-4ubuntu0.1~esm1
canonicalubuntu_linux
debianaudiofile< audiofile 0.3.6-5 (bookworm)audiofile 0.3.6-5 (bookworm)

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.