Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7247
HistoryAug 07, 2018 - 5:40 a.m.

Heap-based Buffer Overflow

2018-08-0705:40:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.11 Low

EPSS

Percentile

95.1%

libsndfile is vulnerable to heap-based buffer overflow. This is due to the wrong management of the headindex and headend values while parsing AIFF header values. An attacker is able to exploit this vulnerability to overwrite memory heap by manipulating index values to use memcpy() via a malicious AIFF file.

CPENameOperatorVersion
libsndfile.sole1.0.25