Vulnerabilities In Sound Processing Library Libsndfile


Recommended Posts

18 May 2009, 16:36

Vulnerabilities in sound processing library libsndfile

"Two vulnerabilities in the open source sound processing library libsndfile could allow an attacker to compromise a system by playing a media file. A heap buffer overflow can be triggered when playing back specially crafted Creative Labs Audio Files (VOC) and AIFF files. The libsndfile library has been updated to version 1.0.20 which fixes the issues.

Version 5.552 of the Winamp media player is affected as it uses the library. An update for Winamp, however, is not yet officially available."

See also:

libsndfile/Winamp VOC Processing Heap Buffer Overflow, advisory from Tobias Klein.

libsndfile 1.0.20., description of the new version.

Source: Heise security - http://www.h-online.com/security/Vulnerabi...e--/news/113313

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...