CVE-2020-18781

Name
CVE-2020-18781
Description
Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/mpruett/audiofile/issues/56

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:audiofile:audiofile:0.3.6:*:*:*:*:*:*:* audiofile == None == 0.3.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
audiofile edge-community 0.3.6-r3 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
audiofile 3.18-community 0.3.6-r2 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
audiofile 3.19-community 0.3.6-r3 Bart Ribbers <bribbers@disroot.org> possibly vulnerable