Lucene search

K
nvd[email protected]NVD:CVE-2014-9496
HistoryJan 16, 2015 - 4:59 p.m.

CVE-2014-9496

2015-01-1616:59:16
web.nvd.nist.gov

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

8.5 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.5%

The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.

Affected configurations

NVD
Node
libsndfile_projectlibsndfileRange<1.0.26
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
Node
debiandebian_linuxMatch9.0
Node
canonicalubuntu_linuxMatch12.04esm
OR
canonicalubuntu_linuxMatch14.04esm
OR
canonicalubuntu_linuxMatch15.04
OR
canonicalubuntu_linuxMatch15.10
Node
oraclesolarisMatch11.2

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

8.5 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.5%