Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-13440

Опубликовано: 07 июл. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.

Отчет

Red Hat Product Security has rated this issue as having a security impact of Low, and a future update may address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5audiofileNot affected
Red Hat Enterprise Linux 6audiofileNot affected
Red Hat Enterprise Linux 8audiofileWill not fix
Red Hat Enterprise Linux 7audiofileFixedRHSA-2020:387729.09.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1600367audiofile: NULL pointer dereference in ModuleState::setup() in modules/ModuleState.cpp allows for denial of service via crafted file

EPSS

Процентиль: 90%
0.06018
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.

CVSS3: 6.5
nvd
больше 7 лет назад

The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.

CVSS3: 6.5
debian
больше 7 лет назад

The audiofile Audio File Library 0.3.6 has a NULL pointer dereference ...

suse-cvrf
почти 7 лет назад

Security update for audiofile

suse-cvrf
больше 5 лет назад

Security update for audiofile

EPSS

Процентиль: 90%
0.06018
Низкий

5.3 Medium

CVSS3