In association with heise online

18 May 2009, 15:36

Vulnerabilities in sound processing library libsndfile

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

Two vulnerabilities in the open source sound processing library libsndfile could allow an attacker to compromise a system by playing a media file. A heap buffer overflow can be triggered when playing back specially crafted Creative Labs Audio Files (VOC) and AIFF files. The libsndfile library has been updated to version 1.0.20 which fixes the issues.

Version 5.552 of the Winamp media player is affected as it uses the library. An update for Winamp, however, is not yet officially available.

See also:


Print Version | Send by email | Permalink:

  • July's Community Calendar

The H Open

The H Security

The H Developer

The H Internet Toolkit