Msrc Cm1 Libsndfile 1.0.31-1 On Cbl Mariner 1.0 vulnerabilities
13 known vulnerabilities affecting msrc/cm1_libsndfile_1.0.31-1_on_cbl_mariner_1.0.
Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM8
Vulnerabilities
Page 1 of 1
CVE-2019-3832MEDIUMCVSS 5.02019-03-12
CVE-2019-3832 [MEDIUM] CWE-125 It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this
It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.
FAQ: Is Azure Linux the only Mi
msrc
CVE-2018-19662HIGHCVSS 8.12018-11-13
CVE-2018-19662 [HIGH] CWE-125 An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of service.
An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main be
msrc
CVE-2018-19758MEDIUMCVSS 6.52018-11-13
CVE-2018-19758 [MEDIUM] CWE-125 There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.
There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azur
msrc
CVE-2018-19432MEDIUMCVSS 6.52018-11-13
CVE-2018-19432 [MEDIUM] CWE-476 An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c which will lead to a denial of service.
An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c which will lead to a denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnera
msrc
CVE-2018-19661MEDIUMCVSS 6.52018-11-13
CVE-2018-19661 [MEDIUM] CWE-125 An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service.
An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main
msrc
CVE-2018-13139HIGHCVSS 8.82018-07-10
CVE-2018-13139 [HIGH] CWE-787 A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a cr
A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file. The vulnerability can be triggered by the executabl
msrc
CVE-2018-13419MEDIUMCVSS 6.52018-07-10
CVE-2018-13419 [MEDIUM] CWE-772 An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce and
An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce and closed the issue
FAQ: Is Azure Linux the only Microsoft product t
msrc
CVE-2017-14245HIGHCVSS 8.12017-09-12
CVE-2017-14245 [HIGH] CWE-125 An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure related to mishandling of the NAN and INFINITY floating-po
An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure related to mishandling of the NAN and INFINITY floating-point values.
FAQ: Is Azure Linux the only Microsoft product that incl
msrc
CVE-2017-14246HIGHCVSS 8.12017-09-12
CVE-2017-14246 [HIGH] CWE-125 An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure related to mishandling of the NAN and INFINITY floating-po
An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure related to mishandling of the NAN and INFINITY floating-point values.
FAQ: Is Azure Linux the only Microsoft product that incl
msrc
CVE-2017-14634MEDIUMCVSS 6.52017-09-12
CVE-2017-14634 [MEDIUM] CWE-369 In libsndfile 1.0.28 a divide-by-zero error exists in the function double64_init() in double64.c which may lead to DoS when playing a crafted audio file.
In libsndfile 1.0.28 a divide-by-zero error exists in the function double64_init() in double64.c which may lead to DoS when playing a crafted audio file.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the m
msrc
CVE-2017-8361HIGHCVSS 8.82017-04-11
CVE-2017-8361 [HIGH] CWE-119 The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.
FAQ: Is Azure Linux the only Microsoft product
msrc
CVE-2017-8362MEDIUMCVSS 6.52017-04-11
CVE-2017-8362 [MEDIUM] CWE-125 The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially
msrc
CVE-2017-8363MEDIUMCVSS 6.52017-04-11
CVE-2017-8363 [MEDIUM] CWE-125 The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source librar
msrc