PT-2009-6670 · Erik De Castro Lopo · Libsndfile1-Dev+2

Alin Rad Pop

·

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2009-0186

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libsndfile versions prior to 1.0.19 libsndfile1-dev (affected versions not specified) sndfile-programs (affected versions not specified)
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. An integer overflow in libsndfile 1.0.18 allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.
Recommendations For libsndfile versions prior to 1.0.19, update to version 1.0.19 or later to resolve the issue. For libsndfile1-dev, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For sndfile-programs, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01928
BDU:2015-01929
BDU:2015-01930
BDU:2015-09377
CVE-2009-0186
DSA-1742-1
DTSA-202-1
OPENSUSE-SU-2024:10148-1
OPENSUSE-SU-2024:10470-1

Produtos afetados

Libsndfile
Libsndfile1-Dev
Sndfile-Programs