|
|
| |
|
| |
libsndfile: arbitrary code execution
| Package(s): | libsndfile |
CVE #(s): | CVE-2009-1788
CVE-2009-1791
|
| Created: | May 28, 2009 |
Updated: | December 4, 2009 |
| Description: |
libsndfile has a pair of arbitrary code execution vulnerabilities.
From the Gentoo alert:
Tobias Klein reported that the header_read() function in
src/common.c uses user input for calculating a buffer size, possibly
leading to a heap-based buffer overflow (CVE-2009-1788).
The vendor reported a boundary error in the aiff_read_header()
function in src/aiff.c, possibly leading to a heap-based buffer
overflow (CVE-2009-1791). |
| Alerts: |
|
( Log in to post comments)
|
|
|