Published: 08 July 2018
The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.
CVSS 3 base score: 6.5
Launchpad, Ubuntu, Debian
|Ubuntu 21.04 (Hirsute Hippo)||
|Ubuntu 20.04 LTS (Focal Fossa)||
|Ubuntu 18.04 LTS (Bionic Beaver)||
|Ubuntu 16.04 ESM (Xenial Xerus)||
(end of standard support, was needed)
|Ubuntu 14.04 ESM (Trusty Tahr)||
It looks like upstream is not active anymore, some of the open CVEs have a proposed fix on a fork. Marking as deferred for now.