CVE-2018-19662 is a buffer over-read vulnerability in libsndfile version 1.0.28, specifically within the i2alaw_array function in alaw.c, affecting Debian and libsndfile projects. This flaw carries a high CVSS score of 8.1, indicating it can be exploited remotely with low complexity, requiring user interaction, and leading to a denial of service. Despite its severity, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not currently a high-profile threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.28CPE matchmatch criteria | cpe:2.3:a:libsndfile_project:libsndfile:1.0.28:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
CVE-2018-19662
Jan 12, 2021libsndfile: buffer over-read in the function i2alaw_array in alaw.c
Nov 27, 2018An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of service.
Nov 13, 2018