Description
It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1712-1 | libsndfile security update |
Debian DLA |
DLA-2418-1 | libsndfile security update |
EUVD |
EUVD-2019-13452 | It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash. |
Ubuntu USN |
USN-4013-1 | libsndfile vulnerabilities |
Ubuntu USN |
USN-4704-1 | libsndfile vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T19:19:18.550Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3832
No data.
Status : Modified
Published: 2019-03-21T16:01:04.797
Modified: 2024-11-21T04:42:38.340
Link: CVE-2019-3832
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN