|
|
| |
| "Libsndfile is a C library for reading and writing files containing sampled sound (such as MS Windows WAV and the Apple/SGI AIFF format) through one standard library interface." Secunia Research has discovered a vulnerability in libsndfile, which can be exploited by malicious people to compromise an application using the library. |
| |
Credit:
The information has been provided by Secunia Research.
The original article can be found at: http://secunia.com/secunia_research/2009-7/
|
| |
Vulnerable Systems:
* libsndfile version 1.0.18
Immune Systems:
* libsndfile version 1.0.19
The vulnerability is caused due to an integer overflow error in the processing of CAF description chunks. This can be exploited to cause a heap-based buffer overflow by tricking the user into processing aspecially crafted CAF audio file.
Successful exploitation may allow execution of arbitrary code.
CVE Information:
CVE-2009-0186
Time Table:
20/02/2009 - Vendor notified.
21/02/2009 - Vendor response.
03/03/2009 - Public disclosure.
|
|
|