Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-18781

Опубликовано: 25 авг. 2023
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.

A vulnerability was found in audiofile, where heap buffer overflow vulnerability was discovered in FilePOSIX::read in File.cpp leads to denial of service via a crafted wav file, this bug can be triggered by the executable sfconvert.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7audiofileOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2235372audiofile: a Denial of Service via crafted file

EPSS

Процентиль: 8%
0.00029
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.

CVSS3: 5.5
nvd
больше 2 лет назад

Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.

CVSS3: 5.5
debian
больше 2 лет назад

Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in a ...

CVSS3: 5.5
github
больше 2 лет назад

Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.

EPSS

Процентиль: 8%
0.00029
Низкий

5.5 Medium

CVSS3