In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libsndfile | Jun 15, 2017 | Jun 12, 2017 |
| Freebsd | — | Upgrade linux-c7-libsndfileUpgrade libsndfileUpgrade linux-c6-libsndfile | Mar 2, 2018 | Mar 1, 2018 |
| Gentoo Linux | — | Upgrade media-libs/libsndfile. | Dec 3, 2018 | Jun 12, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libsndfile | Dec 4, 2019 | Jun 12, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libsndfile | Feb 15, 2019 | Jun 12, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libsndfile | Nov 19, 2019 | Jun 12, 2017 |
| Oracle Solaris | — | Upgrade library/libsndfile to version 1.0.28-11.4.4.0.1.2.0 on Solaris 11.4 | Dec 17, 2018 | Jun 12, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 23, 2017 |
| Suse | — | Upgrade libsndfile-develUpgrade libsndfile1Upgrade libsndfile1-32bit | Feb 4, 2018 | Jun 12, 2017 |
| Ubuntu | — | Upgrade libsndfile1 (Ubuntu Pro)Upgrade libsndfile1Upgrade sndfile-programs (Ubuntu Pro)Upgrade sndfile-programs | Jun 10, 2019 | Jun 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub