Lucene search

K
osvGoogleOSV:USN-5409-1
HistoryMay 10, 2022 - 6:49 p.m.

libsndfile vulnerability

2022-05-1018:49:47
Google
osv.dev
6
libsndfile
vulnerability
memory management
flac codec
denial of service
sensitive information
software

AI Score

7.2

Confidence

High

EPSS

0.003

Percentile

71.7%

It was discovered that libsndfile was incorrectly performing memory
management operations and incorrectly using buffers when executing
its FLAC codec. If a user or automated system were tricked into
processing a specially crafted sound file, an attacker could
possibly use this issue to cause a denial of service or obtain
sensitive information.