An off-by-one error in function wavreadheader in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Service or other unspecified impacts.
{
"binaries": [
{
"binary_name": "libsndfile1",
"binary_version": "1.0.25-10ubuntu0.16.04.3+esm4"
},
{
"binary_name": "libsndfile1-dev",
"binary_version": "1.0.25-10ubuntu0.16.04.3+esm4"
},
{
"binary_name": "sndfile-programs",
"binary_version": "1.0.25-10ubuntu0.16.04.3+esm4"
}
]
}