LWN.net Logo

libsndfile: arbitrary code execution

Package(s):libsndfile CVE #(s):CVE-2011-2696
Created:July 21, 2011 Updated:September 7, 2011
Description: From the Red Hat advisory:

An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way the libsndfile library processed certain Ensoniq PARIS Audio Format (PAF) audio files. An attacker could create a specially-crafted PAF file that, when opened, could cause an application using libsndfile to crash or, potentially, execute arbitrary code with the privileges of the user running the application.

Alerts:
Fedora FEDORA-2011-9319 2011-07-15
Pardus 2011-103 2011-08-04
openSUSE openSUSE-SU-2011:0855-1 2011-08-01
openSUSE openSUSE-SU-2011:0854-1 2011-07-29
Debian DSA-2288-1 2011-07-28
Ubuntu USN-1174-1 2011-07-25
Mandriva MDVSA-2011:119 2011-07-25
Fedora FEDORA-2011-9325 2011-07-15
Scientific Linux SL-libs-20110720 2011-07-20
Red Hat RHSA-2011:1084-01 2011-07-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds