Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-52194

Опубликовано: 21 авг. 2025
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.

A flaw was found in the libsndfile library. A buffer overflow can be triggered when a specially crafted IRCAM audio file is processed, specifically when attempting to set the sample rate. This issue can cause a crash to the application linked to the library and result in a denial of service.

Отчет

To exploit this flaw, an attacker needs to be able to process a specially crafted IRCAM audio file with the application linked to the libsndfile library. Additionally, this issue can cause memory corruption, but the most likely impact is an application crash via a SIGILL signal due to an illegal instruction. Due to these reasons, this vulnerability has been rated with a Moderate severity.

Меры по смягчению последствий

Do not process untrusted IRCAM audio files with the libsndfile library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsndfileNot affected
Red Hat Enterprise Linux 6libsndfileOut of support scope
Red Hat Enterprise Linux 7libsndfileNot affected
Red Hat Enterprise Linux 8libsndfileNot affected
Red Hat Enterprise Linux 9libsndfileNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2390103libsndfile: buffer overflow when processing crafted IRCAM audio files

EPSS

Процентиль: 41%
0.00194
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 месяцев назад

A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.

CVSS3: 7.5
nvd
7 месяцев назад

A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.

msrc
около 1 месяца назад

A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.

CVSS3: 7.5
debian
7 месяцев назад

A buffer overflow vulnerability exists in libsndfile version 1.2.2 and ...

CVSS3: 7.5
github
7 месяцев назад

A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.

EPSS

Процентиль: 41%
0.00194
Низкий

8.2 High

CVSS3