Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade audiofileUpgrade audiofile-develUpgrade audiofile-debuginfo | Jul 23, 2024 | Feb 19, 2020 |
| Debian | — | Upgrade audiofile | Jul 30, 2024 | Feb 19, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 19, 2020 |
| Suse | — | Upgrade libaudiofile1-32bitUpgrade libaudiofile1Upgrade audiofile-develUpgrade audiofile | Dec 18, 2015 | Oct 28, 2015 |
| Ubuntu | — | Upgrade libaudiofile1 | Nov 9, 2015 | Oct 28, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub