Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libsndfile | Aug 30, 2017 | Nov 17, 2015 |
| Debian | — | Upgrade libsndfile | Mar 31, 2017 | Nov 17, 2015 |
| Gentoo Linux | — | Upgrade media-libs/libsndfile. | Oct 30, 2017 | Nov 17, 2015 |
| Huawei Euleros 2_0_sp1 | — | Upgrade libsndfile | Nov 30, 2017 | Nov 17, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libsndfile | Nov 30, 2017 | Nov 17, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 12, 2015 |
| Suse | — | Upgrade libsndfileUpgrade libsndfile1-32bitUpgrade libsndfile-32bitUpgrade libsndfile1Upgrade libsndfile-develUpgrade libsndfile-x86 | Dec 18, 2015 | Nov 12, 2015 |
| Ubuntu | — | Upgrade libsndfile1 | Dec 8, 2015 | Nov 17, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub