PT-2024-34358 · Unknown+9 · Libsndfile+9

4N0Nym4U5

·

Published

2024-10-27

·

Updated

2025-10-31

·

CVE-2024-50612

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: libsndfile versions prior to 1.2.3
Description: The issue is related to an out-of-bounds read in the ogg vorbis.c component of the libsndfile library, specifically in the vorbis analysis wrote() function. This could potentially allow an attacker to execute arbitrary code on the target system.
Recommendations: For libsndfile versions prior to 1.2.3, consider updating to version 1.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the vorbis analysis wrote() function in ogg vorbis.c until a patch is available.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:11192
ALSA-2024:11237
AZL-51891
AZL-52166
BDU:2025-03333
CESA-2024_11192
CVE-2024-50612
INFSA-2024_11192
INFSA-2024_11237
MGASA-2024-0373
OESA-2024-2559
OESA-2025-2571
OESA-2025-2572
OESA-2025-2573
OPENSUSE-SU-2024:14532-1
RHSA-2024:11172
RHSA-2024:11192
RHSA-2024:11237
RHSA-2024_11192
RHSA-2024_11237
RLSA-2024:11237
ROSA-SA-2025-2574
USN-7267-1
USN-7267-2
USN-7273-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu
Libsndfile