ISOMAN

CVE

CVE-2019-3832

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

Severity
MEDIUM
CVSS
5.5
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3832
  2. https://github.com/erikd/libsndfile/issues/456
  3. https://github.com/erikd/libsndfile/pull/460
  4. https://lists.debian.org/debian-lts-announce/2020/10/msg00030.html
  5. https://security.gentoo.org/glsa/202007-65
  6. https://usn.ubuntu.com/4013-1/
  7. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3832
  8. https://github.com/erikd/libsndfile/issues/456
  9. https://github.com/erikd/libsndfile/pull/460
  10. https://lists.debian.org/debian-lts-announce/2020/10/msg00030.html
  11. https://security.gentoo.org/glsa/202007-65
  12. https://usn.ubuntu.com/4013-1/