The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libsndfile | Mar 31, 2017 | Jan 16, 2015 |
| Gentoo Linux | — | Upgrade media-libs/libsndfile. | Oct 30, 2017 | Jan 16, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libsndfile | Dec 4, 2019 | Jan 16, 2015 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libsndfile | Sep 25, 2019 | Jan 16, 2015 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libsndfile | Nov 19, 2019 | Jan 16, 2015 |
| Oracle Solaris | — | Upgrade library/libsndfile to version 1.0.23-0.175.2.7.0.2.0 on Solaris 11.2 | May 29, 2017 | Jan 16, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 22, 2014 |
| Suse | — | Upgrade libsndfile-develUpgrade libsndfile1Upgrade libsndfile1-32bitUpgrade libsndfile-x86Upgrade libsndfile-32bitUpgrade libsndfile | Dec 18, 2015 | Jan 16, 2015 |
| Ubuntu | — | Upgrade libsndfile1 | Dec 8, 2015 | Jan 16, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub