Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3832

Опубликовано: 07 фев. 2019
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

It was discovered the fix for CVE-2018-19758 was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libsndfileWill not fix
Red Hat Enterprise Linux 7libsndfileFix deferred
Red Hat Enterprise Linux 8libsndfileFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1677216libsndfile: incomplete fix for CVE-2018-19758 still allow to read beyond buffer limits

EPSS

Процентиль: 30%
0.00114
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

CVSS3: 5.5
nvd
почти 7 лет назад

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

CVSS3: 5
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 5.5
debian
почти 7 лет назад

It was discovered the fix for CVE-2018-19758 (libsndfile) was not comp ...

CVSS3: 5
github
больше 3 лет назад

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

EPSS

Процентиль: 30%
0.00114
Низкий

3.3 Low

CVSS3