Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.2.10.20090623-dfsg-4", "binary_name": "libsnack-alsa" }, { "binary_version": "2.2.10.20090623-dfsg-4", "binary_name": "libsnack-oss" }, { "binary_version": "2.2.10.20090623-dfsg-4", "binary_name": "python-tksnack" }, { "binary_version": "2.2.10.20090623-dfsg-4", "binary_name": "tcl-snack" }, { "binary_version": "2.2.10.20090623-dfsg-4", "binary_name": "tcl-snack-dev" }, { "binary_version": "2.2.10.20090623-dfsg-4", "binary_name": "tcl-snack-doc" } ] }