CVE-2018-19661 is a buffer over-read vulnerability in libsndfile 1.0.28, specifically within the i2ulaw_array function in ulaw.c, affecting Debian and libsndfile projects. Rated Medium with a CVSS score of 6.5, it can be triggered remotely with low attack complexity, leading to a denial of service. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.28CPE matchmatch criteria | cpe:2.3:a:libsndfile_project:libsndfile:1.0.28:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-19661
Jan 12, 2021libsndfile: buffer over-read in the function i2ulaw_array in ulaw.c
Nov 27, 2018An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service.
Nov 13, 2018