libsndfile Project libsndfile 1.0.21

CPE Details

libsndfile Project libsndfile 1.0.21
1.0.21
2019-11-21
14h37 +00:00
2019-11-21
14h37 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:libsndfile_project:libsndfile:1.0.21:*:*:*:*:*:*:*

Informations

Vendor

libsndfile_project

Product

libsndfile

Version

1.0.21

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-50612 2024-10-26 22h00 +00:00 libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
5.5
Medium
CVE-2024-50613 2024-10-26 22h00 +00:00 libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.
6.5
Medium
CVE-2017-7741 2017-04-12 16h00 +00:00 In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.
5.5
Medium
CVE-2017-7742 2017-04-12 16h00 +00:00 In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with read memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.
5.5
Medium
CVE-2017-7585 2017-04-07 18h00 +00:00 In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.
5.5
Medium
CVE-2017-7586 2017-04-07 18h00 +00:00 In libsndfile before 1.0.28, an error in the "header_read()" function (common.c) when handling ID3 tags can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.
5.5
Medium
CVE-2014-9756 2015-11-19 19h00 +00:00 The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.
5
CVE-2014-9496 2015-01-16 15h00 +00:00 The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.
2.1