An issue was discovered in libsndfile 1.0.28. There is a OOB read error in sf_write_int in sndfile.c, which will lead to a denial of service. References: https://github.com/erikd/libsndfile/issues/427
Created libsndfile tracking bugs for this issue: Affects: fedora-all [bug 1652567]
Patch mentioned in upstream bug: https://github.com/erikd/libsndfile/commit/6f3266277bed16525f0ac2f0f03ff4626f1923e5 But appears to need this one, too (fix for CVE-2018-13139): https://github.com/erikd/libsndfile/commit/aaea680337267bfb6d2544da878890ee7f1c5077
Statement: This issue did not affect the versions of libsndfile as shipped with Red Hat Enterprise Linux 6. This issue affects the versions of libsndfile as shipped with Red Hat Enterprise Linux 7.