Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libsndfile | Jul 30, 2024 | May 26, 2009 |
| Freebsd | — | Upgrade libsndfile | Dec 10, 2025 | May 30, 2009 |
| Gentoo Linux | — | Upgrade media-libs/libsndfile. | Oct 30, 2017 | May 26, 2009 |
| Suse | — | Upgrade libsndfile-develUpgrade libsndfile-32bitUpgrade libsndfileUpgrade libsndfile-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libsndfile1 | Nov 8, 2024 | May 26, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub