CVE-2019-13147

Name
CVE-2019-13147
Description
In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/mpruett/audiofile/issues/54
Mailing List https://lists.debian.org/debian-lts-announce/2023/11/msg00006.html
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/07/msg00020.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.6:*:*:*:*:*:*:* audio_file_library == None == 0.3.6
cpe:2.3:a:audiofile:audiofile:0.3.6:*:*:*:*:*:*:* audiofile == None == 0.3.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
audiofile edge-community 0.3.6-r3 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
audiofile 3.22-community 0.3.6-r3 Bart Ribbers <bribbers@disroot.org> possibly vulnerable