PT-2009-6670 · Erik De Castro Lopo · Libsndfile1-Dev+2

Alin Rad Pop

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-0186

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libsndfile versions prior to 1.0.19 libsndfile1-dev (affected versions not specified) sndfile-programs (affected versions not specified)
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. An integer overflow in libsndfile 1.0.18 allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.
Recommendations For libsndfile versions prior to 1.0.19, update to version 1.0.19 or later to resolve the issue. For libsndfile1-dev, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For sndfile-programs, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01928
BDU:2015-01929
BDU:2015-01930
BDU:2015-09377
CVE-2009-0186
DSA-1742-1
DTSA-202-1
OPENSUSE-SU-2024:10148-1
OPENSUSE-SU-2024:10470-1

Affected Products

Libsndfile
Libsndfile1-Dev
Sndfile-Programs