Out-of-bounds read in libsndfile - CVE-2018-19758

 

Out-of-bounds read in libsndfile - CVE-2018-19758

Published: December 3, 2018 / Updated: August 17, 2023


Vulnerability identifier: #VU16205
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19758
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to heap-based buffer overread condition in the wav_write_headerfunction, as defined in the wav.c source code file. A remote attacker can trick the victim into following a custom link or opening a crafted audio file that submits malicious input, trigger memory corruption and perform a denial of service attack.


Affected software

libsndfile
libsndfile (Ubuntu package)
busybox (Alpine package)
libsndfile (Alpine package)
SUSE Linux Enterprise Module for Packagehub Subpackages
firefox-esr (Alpine package)
libsndfile1 (Ubuntu package)
sndfile-programs (Ubuntu package)
libsndfile-debugsource
libsndfile-devel
libsndfile1
libsndfile1-debuginfo
libsndfile1-32bit
libsndfile1-32bit-debuginfo
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
Dell PowerProtect Cyber Recovery

How to mitigate CVE-2018-19758

Install update from vendor's website.

libsndfile (Ubuntu package) - addressed in versions 1.0.25-10ubuntu0.16.04.2, 1.0.28-4ubuntu0.18.04.1, 1.0.28-4ubuntu0.18.10.1
libsndfile (Alpine package) - update to 1.0.28-r5
libsndfile1 (Ubuntu package) - addressed in versions 1.0.25-10ubuntu0.16.04.3, 1.0.2510ubuntu0.16.04.3+esm2
sndfile-programs (Ubuntu package) - addressed in versions 1.0.25-10ubuntu0.16.04.3, 1.0.2510ubuntu0.16.04.3+esm2
libsndfile-debugsource - update to 1.0.28-5.12.1
libsndfile-devel - update to 1.0.28-5.12.1
libsndfile1 - update to 1.0.28-5.12.1
libsndfile1-debuginfo - update to 1.0.28-5.12.1
libsndfile1-32bit - update to 1.0.28-5.12.1
libsndfile1-32bit-debuginfo - update to 1.0.28-5.12.1
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8

External References

Related Security Bulletins