Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2.2.10.20090623-dfsg-4",
"binary_name": "libsnack-alsa"
},
{
"binary_version": "2.2.10.20090623-dfsg-4",
"binary_name": "libsnack-oss"
},
{
"binary_version": "2.2.10.20090623-dfsg-4",
"binary_name": "python-tksnack"
},
{
"binary_version": "2.2.10.20090623-dfsg-4",
"binary_name": "tcl-snack"
},
{
"binary_version": "2.2.10.20090623-dfsg-4",
"binary_name": "tcl-snack-dev"
},
{
"binary_version": "2.2.10.20090623-dfsg-4",
"binary_name": "tcl-snack-doc"
}
]
}