Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.
{ "binaries": [ { "binary_name": "audiofile-tools", "binary_version": "0.3.6-5build1" }, { "binary_name": "audiofile-tools-dbgsym", "binary_version": "0.3.6-5build1" }, { "binary_name": "libaudiofile-dev", "binary_version": "0.3.6-5build1" }, { "binary_name": "libaudiofile1", "binary_version": "0.3.6-5build1" }, { "binary_name": "libaudiofile1-dbgsym", "binary_version": "0.3.6-5build1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "audiofile-tools", "binary_version": "0.3.6-5build1" }, { "binary_name": "audiofile-tools-dbgsym", "binary_version": "0.3.6-5build1" }, { "binary_name": "libaudiofile-dev", "binary_version": "0.3.6-5build1" }, { "binary_name": "libaudiofile1", "binary_version": "0.3.6-5build1" }, { "binary_name": "libaudiofile1-dbgsym", "binary_version": "0.3.6-5build1" } ], "availability": "No subscription required" }