CVE-2019-3832 PUBLISHED

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

EPSS 0.10% · 28.5th percentile

Risk Scores

EPSS Score
0.10%
28.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlibsndfile0, 1.0.25-10ubuntu0.16.04.1, 1.0.25-10
Ubuntu:18.04:LTSlibsndfile1.0.28-4, 0
Ubuntu:Pro:14.04:LTSlibsndfile1.0.25-7ubuntu2.1, 1.0.25-7ubuntu2, 1.0.25-7ubuntu1

Timeline

References

Open in Interactive Console →