libsndfile 'src/sd2.c' Multiple Buffer Overflow Vulnerabilities
BID:71796
Info
libsndfile 'src/sd2.c' Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 71796 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-9496 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2014 12:00AM |
| Updated: | Jul 05 2016 09:25PM |
| Credit: | Joshua Rogers |
| Vulnerable: |
Slackware Linux x86_64 -current Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux -current |
| Not Vulnerable: | |
Discussion
libsndfile 'src/sd2.c' Multiple Buffer Overflow Vulnerabilities
libsndfile is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user supplied input.
Successful exploits may allow an attacker to execute arbitrary code within the context of the user running the affected application or result in denial-of-service conditions.
libsndfile is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user supplied input.
Successful exploits may allow an attacker to execute arbitrary code within the context of the user running the affected application or result in denial-of-service conditions.
Exploit / POC
libsndfile 'src/sd2.c' Multiple Buffer Overflow Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
libsndfile 'src/sd2.c' Multiple Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
libsndfile 'src/sd2.c' Multiple Buffer Overflow Vulnerabilities
References:
References:
- libsndfile Homepage (libsndfile)