Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.
{
"binaries": [
{
"binary_version": "0.3.6-5build1",
"binary_name": "audiofile-tools"
},
{
"binary_version": "0.3.6-5build1",
"binary_name": "audiofile-tools-dbgsym"
},
{
"binary_version": "0.3.6-5build1",
"binary_name": "libaudiofile-dev"
},
{
"binary_version": "0.3.6-5build1",
"binary_name": "libaudiofile1"
},
{
"binary_version": "0.3.6-5build1",
"binary_name": "libaudiofile1-dbgsym"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "0.3.6-5build1",
"binary_name": "audiofile-tools"
},
{
"binary_version": "0.3.6-5build1",
"binary_name": "audiofile-tools-dbgsym"
},
{
"binary_version": "0.3.6-5build1",
"binary_name": "libaudiofile-dev"
},
{
"binary_version": "0.3.6-5build1",
"binary_name": "libaudiofile1"
},
{
"binary_version": "0.3.6-5build1",
"binary_name": "libaudiofile1-dbgsym"
}
],
"availability": "No subscription required"
}