An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.
CVSS Details
- CVSS 3.0 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libsndfile | Feb 20, 2019 | Sep 21, 2017 |
| Freebsd | — | Upgrade libsndfileUpgrade linux-c6-libsndfileUpgrade linux-c7-libsndfile | Mar 2, 2018 | Mar 1, 2018 |
| Gentoo Linux | — | Upgrade media-libs/libsndfile. | Aug 4, 2020 | Sep 21, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade libsndfile | Nov 30, 2017 | Sep 21, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libsndfile | Nov 30, 2017 | Sep 21, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libsndfile | Nov 19, 2019 | Sep 21, 2017 |
| Oracle Solaris | — | Upgrade library/libsndfile to version 1.0.28-11.4.4.0.1.2.0 on Solaris 11.4 | Dec 17, 2018 | Sep 21, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 14, 2017 |
| Suse | — | Upgrade libsndfile-x86Upgrade libsndfile-32bitUpgrade libsndfile-develUpgrade libsndfile1Upgrade libsndfile1-32bitUpgrade libsndfile | Feb 4, 2018 | Sep 21, 2017 |
| Ubuntu | — | Upgrade sndfile-programsUpgrade libsndfile1 (Ubuntu Pro)Upgrade sndfile-programs (Ubuntu Pro)Upgrade libsndfile1 | Jun 10, 2019 | Sep 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub