Wind River Support Network

HomeDefectsLIN10-5168
Fixed

LIN10-5168 : Security Advisory - libsndfile1 - CVE-2018-19758

Created: Dec 19, 2018    Updated: Apr 2, 2019
Resolved Date: Mar 29, 2019
Found In Version: 10.17.41.1
Fix Version: 10.17.41.15
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.

https://nvd.nist.gov/vuln/detail/CVE-2018-19758

CVEs


Live chat
Online