|
|
| |
|
| |
libsndfile: arbitrary code execution
| Package(s): | libsndfile |
CVE #(s): | CVE-2011-2696
|
| Created: | July 21, 2011 |
Updated: | September 7, 2011 |
| Description: |
From the Red Hat advisory:
An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the libsndfile library processed certain Ensoniq PARIS
Audio Format (PAF) audio files. An attacker could create a
specially-crafted PAF file that, when opened, could cause an application
using libsndfile to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. |
| Alerts: |
|
( Log in to post comments)
|
|
|