Lucene search

K
ubuntuUbuntuUSN-1174-1
HistoryJul 25, 2011 - 12:00 a.m.

libsndfile vulnerability

2011-07-2500:00:00
ubuntu.com
39

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.075

Percentile

94.1%

Releases

  • Ubuntu 11.04
  • Ubuntu 10.10
  • Ubuntu 10.04

Packages

  • libsndfile - Library for reading/writing audio files

Details

Hossein Lotfi discovered that libsndfile did not properly verify the header
length and number of channels for PARIS Audio Format (PAF) audio files. An
attacker could exploit this to cause a denial of service via application
crash, or possibly execute arbitrary code with the privileges of the user
invoking the program.

OSVersionArchitecturePackageVersionFilename
Ubuntu11.04noarchlibsndfile1< 1.0.23-1ubuntu0.1UNKNOWN
Ubuntu11.04noarchlibsndfile1-dev< 1.0.23-1ubuntu0.1UNKNOWN
Ubuntu11.04noarchsndfile-programs< 1.0.23-1ubuntu0.1UNKNOWN
Ubuntu10.10noarchlibsndfile1< 1.0.21-2ubuntu0.10.10.1UNKNOWN
Ubuntu10.10noarchlibsndfile1-dev< 1.0.21-2ubuntu0.10.10.1UNKNOWN
Ubuntu10.10noarchsndfile-programs< 1.0.21-2ubuntu0.10.10.1UNKNOWN
Ubuntu10.04noarchlibsndfile1< 1.0.21-2ubuntu0.10.04.1UNKNOWN
Ubuntu10.04noarchlibsndfile1-dev< 1.0.21-2ubuntu0.10.04.1UNKNOWN
Ubuntu10.04noarchsndfile-programs< 1.0.21-2ubuntu0.10.04.1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.075

Percentile

94.1%