Description
The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-5382 | The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert. |
Ubuntu USN |
USN-3800-1 | audiofile vulnerabilities |
Ubuntu USN |
USN-6558-1 | audiofile vulnerabilities |
References
History
Thu, 14 Aug 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Audiofile
Audiofile audiofile |
|
| CPEs | cpe:2.3:a:audiofile:audiofile:0.3.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Audio File Library Project
Audio File Library Project audio File Library |
Audiofile
Audiofile audiofile |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T09:00:35.391Z
Reserved: 2018-07-08T00:00:00.000Z
Link: CVE-2018-13440
No data.
Status : Modified
Published: 2018-07-08T16:29:00.220
Modified: 2025-08-13T20:48:07.470
Link: CVE-2018-13440
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN