Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libsndfile | Sep 20, 2017 | Aug 5, 2017 |
| Debian | — | Upgrade libsndfile | Feb 25, 2019 | Aug 5, 2017 |
| Freebsd | — | Upgrade linux-c6-libsndfileUpgrade libsndfileUpgrade linux-c7-libsndfile | Mar 2, 2018 | Mar 1, 2018 |
| Gentoo Linux | — | Upgrade media-libs/libsndfile. | Dec 3, 2018 | Aug 5, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libsndfile | Dec 4, 2019 | Aug 5, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libsndfile | Dec 18, 2019 | Aug 5, 2017 |
| Oracle Solaris | — | Upgrade library/libsndfile to version 1.0.28-0.175.3.24.0.2.0 on Solaris 11.3 | Sep 19, 2017 | Aug 5, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 5, 2017 |
| Suse | — | Upgrade libsndfile1-32bitUpgrade libsndfile1Upgrade libsndfile-devel | May 20, 2018 | Aug 5, 2017 |
| Ubuntu | — | Upgrade libsndfile1Upgrade sndfile-programsUpgrade libsndfile1 (Ubuntu Pro)Upgrade sndfile-programs (Ubuntu Pro) | Jan 27, 2021 | Aug 5, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub