6.8
CVSSv2

CVE-2011-2696

Published: 27/07/2011 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in libsndfile prior to 1.0.25 allows remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio Format (PAF) file that triggers a heap-based buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mega-nerd libsndfile 1.0.18

mega-nerd libsndfile 1.0.0

mega-nerd libsndfile 1.0.3

mega-nerd libsndfile 1.0.13

mega-nerd libsndfile 1.0.19

mega-nerd libsndfile 1.0.15

mega-nerd libsndfile 1.0.6

mega-nerd libsndfile 0.0.8

mega-nerd libsndfile 1.0.10

mega-nerd libsndfile 0.0.28

mega-nerd libsndfile 1.0.21

mega-nerd libsndfile 1.0.7

mega-nerd libsndfile 1.0.9

mega-nerd libsndfile 1.0.22

mega-nerd libsndfile 1.0.17

mega-nerd libsndfile 1.0.20

mega-nerd libsndfile

mega-nerd libsndfile 1.0.5

mega-nerd libsndfile 1.0.4

mega-nerd libsndfile 1.0.14

mega-nerd libsndfile 1.0.12

mega-nerd libsndfile 1.0.11

mega-nerd libsndfile 1.0.23

mega-nerd libsndfile 1.0.1

mega-nerd libsndfile 1.0.8

mega-nerd libsndfile 1.0.16

mega-nerd libsndfile 1.0.2

Vendor Advisories

An application using libsndfile could be made to crash or possibly run programs as your login if it opened a specially crafted file ...
Hossein Lotfi discovered an integer overflow in libsndfile's code to parse Paris Audio files, which could potentially lead to the execution of arbitrary code For the oldstable distribution (lenny), this problem has been fixed in version 1017-4+lenny3 For the stable distribution (squeeze), this problem has been fixed in version 1021-3+squeeze1 ...