PT-2010-1643 · Erik De Castro Lopo · Libsndfile
Sami Liedes
·
Published
2010-05-05
·
Updated
2010-05-11
·
CVE-2009-4835
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libsndfile version 1.0.20
Description
The issue allows context-dependent attackers to cause a denial of service, resulting in a divide-by-zero error and application crash, via a crafted audio file. This is due to vulnerabilities in several functions, including
htk read header, alaw init, ulaw init, pcm init, float32 init, and sds read header.Recommendations
For libsndfile version 1.0.20, consider disabling the use of the vulnerable functions until a patch is available. Restrict access to crafted audio files to minimize the risk of exploitation. Avoid using the vulnerable functions in the affected library until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libsndfile