In association with heise online

4 March 2009, 13:39

Vulnerability in sound processing library libsndfile

A vulnerability has been found in the open source sound processing library libsndfile which makes it possible for an attacker to compromise a system by playing a specially crafted CAF audio file. According to Secunia Research, the problem is caused by an integer overflow when processing the manipulated description fields, which can provoke a heap-based buffer overflow, allowing for the injection and execution of arbitrary code.

The problem can be found in versions up to and including 1.0.18. The 1.0.19 update fixes the problem. Any audio player application that uses the library, Winamp for example, is vulnerable. Winamp 5.541, 5.55 and likely previous versions include the flawed libsndfile. An official Winamp update is not yet available to address the issue.

See also:

(crve)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit






The H open source

The H Security

The H Internet Toolkit