Описание
libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
A flaw was found in the libsndfile package. A specially crafted input file may trigger an out-of-bounds read, leading to memory corruption and a denial of service.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 10 | libsndfile | Not affected | ||
Red Hat Enterprise Linux 7 | libsndfile | Out of support scope | ||
Red Hat Enterprise Linux 8 | libsndfile | Fixed | RHSA-2024:11192 | 17.12.2024 |
Red Hat Enterprise Linux 9 | libsndfile | Fixed | RHSA-2024:11237 | 17.12.2024 |
Red Hat Enterprise Linux 9.4 Extended Update Support | libsndfile | Fixed | RHSA-2024:11172 | 17.12.2024 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2322057libsndfile: Segmentation fault error in ogg_vorbis.c:417 vorbis_analysis_wrote()
5.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.5
ubuntu
8 месяцев назад
libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
CVSS3: 5.5
nvd
8 месяцев назад
libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
CVSS3: 5.5
debian
8 месяцев назад
libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out ...
5.5 Medium
CVSS3