Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3246

Опубликовано: 20 июл. 2021
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.

A heap buffer overflow flaw was found in libsndfile. This flaw allows an attacker to execute arbitrary code via a crafted WAV file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libsndfileOut of support scope
Red Hat Enterprise Linux 9libsndfileNot affected
Red Hat Enterprise Linux 7libsndfileFixedRHSA-2021:329530.08.2021
Red Hat Enterprise Linux 8libsndfileFixedRHSA-2021:325324.08.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportlibsndfileFixedRHSA-2021:329730.08.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportlibsndfileFixedRHSA-2021:329830.08.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1984319libsndfile: Heap buffer overflow via crafted WAV file allows arbitrary code execution

EPSS

Процентиль: 78%
0.01201
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.

CVSS3: 8.8
nvd
около 4 лет назад

A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.

CVSS3: 8.8
debian
около 4 лет назад

A heap buffer overflow vulnerability in msadpcm_decode_block of libsnd ...

suse-cvrf
около 4 лет назад

Security update for libsndfile

rocky
почти 4 года назад

Important: libsndfile security update

EPSS

Процентиль: 78%
0.01201
Низкий

8.8 High

CVSS3