PT-2010-1643 · Erik De Castro Lopo · Libsndfile
Sami Liedes
·
Publicado
2010-05-05
·
Atualizado
2010-05-11
·
CVE-2009-4835
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libsndfile version 1.0.20
Description
The issue allows context-dependent attackers to cause a denial of service, resulting in a divide-by-zero error and application crash, via a crafted audio file. This is due to vulnerabilities in several functions, including
htk read header, alaw init, ulaw init, pcm init, float32 init, and sds read header.Recommendations
For libsndfile version 1.0.20, consider disabling the use of the vulnerable functions until a patch is available. Restrict access to crafted audio files to minimize the risk of exploitation. Avoid using the vulnerable functions in the affected library until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Libsndfile