Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-13419

Опубликовано: 05 июл. 2018
Источник: redhat
CVSS3: 6.5

Описание

An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce and closed the issue

A flaw was found in libsndfile. A remote attacker could exploit a memory leak vulnerability in the psf_allocate() function within common.c. By processing a specially crafted file, an attacker could cause the application to consume excessive memory, leading to a Denial of Service (DoS) condition.

Отчет

This is a moderate vulnerabilty where a memory leak flaw in libsndfile could lead to a denial of service if an application processes a specially crafted file. Red Hat Enterprise Linux 6, 7, and 8 are not affected by this vulnerability. Red Hat Enterprise Linux 9 was affected but has since been resolved.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libsndfileNot affected
Red Hat Enterprise Linux 7libsndfileNot affected
Red Hat Enterprise Linux 8libsndfileNot affected
Red Hat Enterprise Linux 9libsndfileAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1599152libsndfile: libsndfile: Denial of Service via memory leak in psf_allocate()

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 8 лет назад

An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce and closed the issue

CVSS3: 6.5
nvd
около 8 лет назад

An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce and closed the issue

CVSS3: 6.5
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 6.5
debian
около 8 лет назад

An issue has been found in libsndfile 1.0.28. There is a memory leak i ...

CVSS3: 6.5
github
около 4 лет назад

** DISPUTED ** An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce and closed the issue.

6.5 Medium

CVSS3