High severity8.8NVD Advisory· Published Sep 16, 2018· Updated Jun 17, 2026
CVE-2018-17095
CVE-2018-17095
Description
An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- osv-coords10 versionspkg:rpm/opensuse/audiofile&distro=openSUSE%20Tumbleweedpkg:rpm/suse/audiofile&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/audiofile&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/audiofile&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015pkg:rpm/suse/audiofile&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/audiofile&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/audiofile&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/audiofile&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/audiofile&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/audiofile&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4
< 0.3.6-11.13+ 9 more
- (no CPE)range: < 0.3.6-11.13
- (no CPE)range: < 0.3.6-11.3.1
- (no CPE)range: < 0.3.6-11.3.1
- (no CPE)range: < 0.3.6-3.3.1
- (no CPE)range: < 0.3.6-11.3.1
- (no CPE)range: < 0.3.6-11.3.1
- (no CPE)range: < 0.3.6-11.3.1
- (no CPE)range: < 0.3.6-11.3.1
- (no CPE)range: < 0.3.6-11.3.1
- (no CPE)range: < 0.3.6-11.3.1
Patches
Vulnerability mechanics
References
3- usn.ubuntu.com/3800-1/nvdPatchVendor Advisory
- github.com/mpruett/audiofile/issues/50nvdExploitIssue TrackingThird Party Advisory
- github.com/mpruett/audiofile/issues/51nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.