SB2019010306 - Out-of-bounds read in libsndfile (Alpine package)
Published: January 3, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2018-19758)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer overread condition in the wav_write_headerfunction, as defined in the wav.c source code file. A remote attacker can trick the victim into following a custom link or opening a crafted audio file that submits malicious input, trigger memory corruption and perform a denial of service attack.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=83d74e47d53224f58b4350ae12ffbe8f508593e6
- https://git.alpinelinux.org/aports/commit/?id=1245056475ad59a71c91494d1e1820f323e22911
- https://git.alpinelinux.org/aports/commit/?id=afcf91b3195a7e0e88b3c570d405ddd1f4591460
- https://git.alpinelinux.org/aports/commit/?id=eb0e8dee37539898fe7a4d9f95ff1353d3d69519
- https://git.alpinelinux.org/aports/commit/?id=64a969f0cd8a0df31772a84d6b0d9f264c4a337e