Description
An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-3800-1 | audiofile vulnerabilities |
Ubuntu USN |
USN-6558-1 | audiofile vulnerabilities |
References
History
Thu, 14 Aug 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Audiofile
Audiofile audiofile |
|
| CPEs | cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.1:*:*:*:*:*:*:* cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.2:*:*:*:*:*:*:* cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.3:*:*:*:*:*:*:* cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.4:*:*:*:*:*:*:* cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.5:*:*:*:*:*:*:* cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.6:*:*:*:*:*:*:* |
cpe:2.3:a:audiofile:audiofile:0.3.0:*:*:*:*:*:*:* cpe:2.3:a:audiofile:audiofile:0.3.1:*:*:*:*:*:*:* cpe:2.3:a:audiofile:audiofile:0.3.2:*:*:*:*:*:*:* cpe:2.3:a:audiofile:audiofile:0.3.3:*:*:*:*:*:*:* cpe:2.3:a:audiofile:audiofile:0.3.4:*:*:*:*:*:*:* cpe:2.3:a:audiofile:audiofile:0.3.5:*:*:*:*:*:*:* cpe:2.3:a:audiofile:audiofile:0.3.6:*:*:*:*:*:*:* |
| Vendors & Products |
Audio File Library Project
Audio File Library Project audio File Library |
Audiofile
Audiofile audiofile |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:39:59.553Z
Reserved: 2018-09-16T00:00:00.000Z
Link: CVE-2018-17095
No data.
Status : Modified
Published: 2018-09-16T21:29:00.860
Modified: 2025-08-13T20:48:07.470
Link: CVE-2018-17095
OpenCVE Enrichment
No data.
Ubuntu USN