Vulnerabilities in sound processing library libsndfile
Two vulnerabilities in the open source sound processing library libsndfile could allow an attacker to compromise a system by playing a media file. A heap buffer overflow can be triggered when playing back specially crafted Creative Labs Audio Files (VOC) and AIFF files. The libsndfile library has been updated to version 1.0.20 which fixes the issues.
Version 5.552 of the Winamp media player is affected as it uses the library. An update for Winamp, however, is not yet officially available.
See also:
- libsndfile/Winamp VOC Processing Heap Buffer Overflow, advisory from Tobias Klein.
- libsndfile 1.0.20., description of the new version.
(crve)