An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Service or other unspecified impacts.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libsndfile | Mar 21, 2024 | Jul 18, 2023 |
| Amazon_linux_2023 | — | Upgrade libsndfile-utils-debuginfoUpgrade libsndfile-debuginfoUpgrade libsndfile-debugsourceUpgrade libsndfileUpgrade libsndfile-utilsUpgrade libsndfile-devel | Feb 17, 2025 | Sep 13, 2023 |
| Debian | — | No solution exists | May 15, 2025 | Jul 18, 2023 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 18, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub