Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libsndfile | Jul 30, 2024 | Mar 5, 2009 |
| Freebsd | — | Upgrade libsndfile | Dec 10, 2025 | Mar 16, 2009 |
| Gentoo Linux | — | Upgrade media-libs/libsndfile. | Oct 30, 2017 | Mar 4, 2009 |
| Suse | — | Upgrade libsndfile1-32bitUpgrade libsndfile-32bitUpgrade libsndfile-develUpgrade libsndfile1Upgrade libsndfileUpgrade libsndfile-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libsndfile1 | Nov 8, 2024 | Mar 5, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub