DSA-2288-1 libsndfile -- integer overflow

Related Vulnerabilities: CVE-2011-2696  

Hossein Lotfi discovered an integer overflow in libsndfile's code to parse Paris Audio files, which could potentially lead to the execution of arbitrary code. For the oldstable distribution (lenny), this problem has been fixed in version 1.0.17-4+lenny3. For the stable distribution (squeeze), this problem has been fixed in version 1.0.21-3+squeeze1 For the unstable distribution (sid), this problem has been fixed in version 1.0.25-1. We recommend that you upgrade your libsndfile packages.

Debian Security Advisory

DSA-2288-1 libsndfile -- integer overflow

Date Reported:
28 Jul 2011
Affected Packages:
libsndfile
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2011-2696.
More information:

Hossein Lotfi discovered an integer overflow in libsndfile's code to parse Paris Audio files, which could potentially lead to the execution of arbitrary code.

For the oldstable distribution (lenny), this problem has been fixed in version 1.0.17-4+lenny3.

For the stable distribution (squeeze), this problem has been fixed in version 1.0.21-3+squeeze1

For the unstable distribution (sid), this problem has been fixed in version 1.0.25-1.

We recommend that you upgrade your libsndfile packages.