PT-2015-4245 · Erik De Castro Lopo+3 · Libsndfile+3

Published

2015-01-08

·

Updated

2024-06-15

·

CVE-2014-9496

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libsndfile (affected versions not specified)
Description The issue is related to the sd2 parse rsrc fork function in sd2.c in libsndfile, which allows attackers to have an unspecified impact through vectors related to a (1) map offset or (2) rsrc marker. This triggers an out-of-bounds read.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2016-2286
CVE-2014-9496
DLA-356-1
DLA-928-1
DSA-4430-1
MGASA-2015-0015
OPENSUSE-SU-2024:10148-1
OPENSUSE-SU-2024:10470-1
SUSE-SU-2015_0160-1
SUSE-SU-2015_0169-1
USN-2832-1

Affected Products

Alt Linux
Suse
Ubuntu
Libsndfile