Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-17095

Опубликовано: 16 сент. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Средний

Описание

An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:audiofile:audiofile:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.3:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.4:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.5:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.6:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

EPSS

Процентиль: 94%
0.12531
Средний

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

CVSS3: 7
redhat
больше 7 лет назад

An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

CVSS3: 8.8
debian
больше 7 лет назад

An issue has been discovered in mpruett Audio File Library (aka audiof ...

suse-cvrf
около 7 лет назад

Security update for audiofile

suse-cvrf
больше 7 лет назад

Security update for audiofile

EPSS

Процентиль: 94%
0.12531
Средний

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-787