alpine · CVE-2018-17095

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2018-17095: 1 source package rows (audiofile); 3 state rows across 3 repos (3.22-community, 3.23-community, edge-community); fixed 0, open 3.

Description:

An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

cvelogic Threat Intelligence