Integer overflow in libsndfile before 1.0.25 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio Format (PAF) file that triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libsndfile | Jul 30, 2024 | Jul 27, 2011 |
| Freebsd | — | Upgrade libsndfile | Dec 10, 2025 | Sep 12, 2011 |
| Gentoo Linux | — | Upgrade media-libs/libsndfile. | Oct 30, 2017 | Jul 26, 2011 |
| Oracle_linux | — | Upgrade libsndfile-develUpgrade libsndfile | Oct 16, 2024 | Jul 27, 2011 |
| Suse | — | Upgrade libsndfile1-32bitUpgrade libsndfile-x86Upgrade libsndfileUpgrade libsndfile-32bitUpgrade libsndfile-develUpgrade libsndfile1 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libsndfile1 | Nov 8, 2024 | Jul 27, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub