Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libsnack-alsa", "binary_version": "2.2.10.20090623-dfsg-4" }, { "binary_name": "libsnack-oss", "binary_version": "2.2.10.20090623-dfsg-4" }, { "binary_name": "python-tksnack", "binary_version": "2.2.10.20090623-dfsg-4" }, { "binary_name": "tcl-snack", "binary_version": "2.2.10.20090623-dfsg-4" }, { "binary_name": "tcl-snack-dev", "binary_version": "2.2.10.20090623-dfsg-4" }, { "binary_name": "tcl-snack-doc", "binary_version": "2.2.10.20090623-dfsg-4" } ] }