vendor:
libsndfile
by:
Marco Romano
7,8
CVSS
HIGH
Heap overflow
119
CWE
Product Name: libsndfile
Affected Version From: <= 1.0.25
Affected Version To: <= 1.0.25
Patch Exists: YES
Related CWE: CVE-2015-7805
CPE: a:mega-nerd:libsndfile
Metasploit:
https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2015-7805/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2015-7805/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2015-7805/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp1-cve-2015-7805/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2015-7805/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2015-7805/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-7805/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 15.04, OS X El Capitan 10.11
2015
libsndfile <= 1.0.25 (latest version) Heap overflow
PoC for libsndfile <= 1.0.25 (latest version) Heap overflow. Possible attack vectors include Firefox (on Linux) -> SWF/Audio play -> pulseaudio -> libsndfile, email attachment, TCP socket connection (for audio server only), file upload (ex. server side audio file manipulation, interactive voice responder), etc. Affected products include PulseAudio, Jack AudioConnectionKit, Adobe Audition, Audacity, Asterisk-eSpeak Module, and other products using libsndfile.
Mitigation:
Update to the latest version of libsndfile.