In association with heise online

18 May 2009, 16:36

Vulnerabilities in sound processing library libsndfile

Two vulnerabilities in the open source sound processing library libsndfile could allow an attacker to compromise a system by playing a media file. A heap buffer overflow can be triggered when playing back specially crafted Creative Labs Audio Files (VOC) and AIFF files. The libsndfile library has been updated to version 1.0.20 which fixes the issues.

Version 5.552 of the Winamp media player is affected as it uses the library. An update for Winamp, however, is not yet officially available.

See also:

(crve)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit






The H open source

The H Security

The H Internet Toolkit