libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-libsndfilealma-upgrade-libsndfile-develalma-upgrade-libsndfile-utils | Dec 19, 2024 | Oct 27, 2024 | |
| Alpine Linux | alpine-linux-upgrade-libsndfile | Aug 8, 2025 | Oct 27, 2024 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-libsndfileamazon-linux-2023-upgrade-libsndfile-debuginfoamazon-linux-2023-upgrade-libsndfile-debugsourceamazon-linux-2023-upgrade-libsndfile-develamazon-linux-2023-upgrade-libsndfile-utilsamazon-linux-2023-upgrade-libsndfile-utils-debuginfo | Mar 27, 2025 | Oct 27, 2024 | |
| Debian | debian-upgrade-libsndfile | May 15, 2025 | Oct 27, 2024 | |
| Oracle_linux | — | oracle-linux-upgrade-libsndfileoracle-linux-upgrade-libsndfile-develoracle-linux-upgrade-libsndfile-utils | Dec 18, 2024 | Oct 27, 2024 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-libsndfileredhat-upgrade-libsndfile-debuginforedhat-upgrade-libsndfile-debugsourceredhat-upgrade-libsndfile-develredhat-upgrade-libsndfile-utilsredhat-upgrade-libsndfile-utils-debuginfo | Feb 10, 2025 | Oct 27, 2024 | |
| Rocky_linux | rocky-upgrade-libsndfilerocky-upgrade-libsndfile-debuginforocky-upgrade-libsndfile-debugsourcerocky-upgrade-libsndfile-develrocky-upgrade-libsndfile-utilsrocky-upgrade-libsndfile-utils-debuginfo | Feb 9, 2026 | Mar 17, 2025 | |
| Ubuntu | ubuntu-pro-upgrade-libsndfile1ubuntu-pro-upgrade-sndfile-programsubuntu-upgrade-libsndfile1ubuntu-upgrade-sndfile-programs | Feb 14, 2025 | Oct 27, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub