UBUNTU-CVE-2015-7805

Source
https://ubuntu.com/security/CVE-2015-7805
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-7805.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2015-7805
Upstream
Downstream
Related
Published
2015-11-17T00:00:00Z
Modified
2025-07-16T07:33:26.303656Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file.

References

Affected packages

Ubuntu:14.04:LTS / libsndfile

Package

Name
libsndfile
Purl
pkg:deb/ubuntu/libsndfile@1.0.25-7ubuntu2.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.25-7ubuntu2.1

Affected versions

1.*

1.0.25-7ubuntu1
1.0.25-7ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "libsndfile1",
            "binary_version": "1.0.25-7ubuntu2.1"
        },
        {
            "binary_name": "libsndfile1-dbg",
            "binary_version": "1.0.25-7ubuntu2.1"
        },
        {
            "binary_name": "libsndfile1-dbgsym",
            "binary_version": "1.0.25-7ubuntu2.1"
        },
        {
            "binary_name": "libsndfile1-dev",
            "binary_version": "1.0.25-7ubuntu2.1"
        },
        {
            "binary_name": "sndfile-programs",
            "binary_version": "1.0.25-7ubuntu2.1"
        },
        {
            "binary_name": "sndfile-programs-dbg",
            "binary_version": "1.0.25-7ubuntu2.1"
        },
        {
            "binary_name": "sndfile-programs-dbgsym",
            "binary_version": "1.0.25-7ubuntu2.1"
        }
    ]
}