Lucene search

K
debianDebianDEBIAN:BSA-059:2DA48
HistoryNov 14, 2011 - 4:20 a.m.

[BSA-059] Security Update for libsndfile

2011-11-1404:20:30
lists.debian.org
14

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.075

Percentile

94.1%

Andres Salomon uploaded new packages for libsndfile which fixed the
following security problems:

CVE-2011-2696
Integer overflow by processing certain PARIS Audio Format (PAF)
files.

For the lenny-backports distribution the problem has been fixed in
version 1.0.21-3+squeeze1~bpo50+1.

For the stable distribution (squeeze), this problem has been fixed in
version 1.0.21-3+squeeze1.
Attachment:
signature.asc
Description: PGP signature

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.075

Percentile

94.1%