7.8
CVSSv3

CVE-2022-33064

Published: 18/07/2023 Updated: 27/07/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an malicious user to execute arbitrary code, Denial of Service or other unspecified impacts.

Vulnerable Product Search on Vulmon Subscribe to Product

libsndfile project libsndfile 1.1.0

Vendor Advisories

Debian Bug report logs - #1051890 libsndfile: CVE-2022-33064 Package: src:libsndfile; Maintainer for src:libsndfile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 13 Sep 2023 21:15:02 UTC Severity: important Tags: security, upstream ...
Description<!---->Libsndfile could allow a remote attacker to execute arbitrary code on the system, caused by an off-by-one error in function wav_read_header in src/wavcLibsndfile could allow a remote attacker to execute arbitrary code on the system, caused by an off-by-one error in function wav_read_header in src/wavc ...