An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.
History

Thu, 14 Aug 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Audiofile
Audiofile audiofile
CPEs cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.3:*:*:*:*:*:*:*
cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.4:*:*:*:*:*:*:*
cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.5:*:*:*:*:*:*:*
cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.6:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.3:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.4:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.5:*:*:*:*:*:*:*
cpe:2.3:a:audiofile:audiofile:0.3.6:*:*:*:*:*:*:*
Vendors & Products Audio File Library Project
Audio File Library Project audio File Library
Audiofile
Audiofile audiofile

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-09-16T21:00:00

Updated: 2024-08-05T10:39:59.553Z

Reserved: 2018-09-16T00:00:00

Link: CVE-2018-17095

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-16T21:29:00.860

Modified: 2025-08-13T20:48:07.470

Link: CVE-2018-17095

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-09-16T00:00:00Z

Links: CVE-2018-17095 - Bugzilla