Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.
{
"binaries": [
{
"binary_name": "audiofile-tools",
"binary_version": "0.3.6-5build1"
},
{
"binary_name": "audiofile-tools-dbgsym",
"binary_version": "0.3.6-5build1"
},
{
"binary_name": "libaudiofile-dev",
"binary_version": "0.3.6-5build1"
},
{
"binary_name": "libaudiofile1",
"binary_version": "0.3.6-5build1"
},
{
"binary_name": "libaudiofile1-dbgsym",
"binary_version": "0.3.6-5build1"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "audiofile-tools",
"binary_version": "0.3.6-5build1"
},
{
"binary_name": "audiofile-tools-dbgsym",
"binary_version": "0.3.6-5build1"
},
{
"binary_name": "libaudiofile-dev",
"binary_version": "0.3.6-5build1"
},
{
"binary_name": "libaudiofile1",
"binary_version": "0.3.6-5build1"
},
{
"binary_name": "libaudiofile1-dbgsym",
"binary_version": "0.3.6-5build1"
}
],
"availability": "No subscription required"
}