6.8
CVSSv2

CVE-2021-3246

Published: 20/07/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows malicious users to execute arbitrary code via a crafted WAV file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libsndfile project libsndfile 1.0.30

fedoraproject fedora 33

fedoraproject fedora 34

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #991496 libsndfile: CVE-2021-3246 Package: src:libsndfile; Maintainer for src:libsndfile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 25 Jul 2021 19:15:01 UTC Severity: grave Tags: security, upstream Found ...
Andrea Fioraldi discovered a buffer overflow in libsndfile, a library for reading/writing audio files, which could result in denial of service or potentially the execution of arbitrary code when processing a malformed audio file For the stable distribution (buster), this problem has been fixed in version 1028-6+deb10u1 We recommend that you upg ...
A heap buffer overflow flaw was found in libsndfile This flaw allows an attacker to execute arbitrary code via a crafted WAV file The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability (CVE-2021-3246) ...
A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1030 allows attackers to execute arbitrary code via a crafted WAV file ...