Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7912
HistoryDec 03, 2018 - 1:17 a.m.

Heap-based Buffer Over-read

2018-12-0301:17:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.002 Low

EPSS

Percentile

55.9%

libsndfile.so is vulnerable to heap-based buffer over-read. The vulnerability exists because wav_write_header in wav.c does not properly handle heap memory allocation, allowing a over-read on address 0x61200000be50.

CPENameOperatorVersion
libsndfile.soeq1.0.20