Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.
{
"binaries": [
{
"binary_name": "libsnack-alsa",
"binary_version": "2.2.10.20090623-dfsg-4"
},
{
"binary_name": "libsnack-oss",
"binary_version": "2.2.10.20090623-dfsg-4"
},
{
"binary_name": "python-tksnack",
"binary_version": "2.2.10.20090623-dfsg-4"
},
{
"binary_name": "tcl-snack",
"binary_version": "2.2.10.20090623-dfsg-4"
},
{
"binary_name": "tcl-snack-dev",
"binary_version": "2.2.10.20090623-dfsg-4"
},
{
"binary_name": "tcl-snack-doc",
"binary_version": "2.2.10.20090623-dfsg-4"
}
],
"availability": "No subscription required"
}