Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2015-7805Improper Restriction of Operations within the Bounds of a Memory Buffer in Libsndfile

Severity
9.3CRITICALNVD
OSV2.1
EPSS
58.5%
top 1.79%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 17
Latest updateMay 14

Description

Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

debiandebian/libsndfile< libsndfile 1.0.25-10 (bookworm)
Debianlibsndfile_project/libsndfile< 1.0.25-10+3
Ubuntulibsndfile_project/libsndfile< 1.0.25-7ubuntu2.1
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

3
GHSA
GHSA-55v7-29g7-7rj7: Heap-based buffer overflow in libsndfile 12022-05-14
OSV
libsndfile vulnerabilities2015-12-07
OSV
CVE-2015-7805: Heap-based buffer overflow in libsndfile 12015-11-17

💥Exploits & PoCs

1
Exploit-DB
libsndfile 1.0.25 - Local Heap Overflow2015-10-13

📋Vendor Advisories

3
Ubuntu
libsndfile vulnerabilities2015-12-07
Red Hat
libsndfile: Heap overflow vulnerability when parsing specially crafted AIFF header2015-10-12
Debian
CVE-2015-7805: libsndfile - Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have ...2015

💬Community

9
Bugzilla
CVE-2015-7805 audacity: libsndfile: Heap overflow vulnerability when parsing specially crafted AIFF header [epel-all]2015-11-04
Bugzilla
CVE-2015-7805 jack-audio-connection-kit: libsndfile: Heap overflow vulnerability when parsing specially crafted AIFF header [epel-all]2015-11-04
Bugzilla
CVE-2015-7805 libsndfile: Heap overflow vulnerability when parsing specially crafted AIFF header [epel-5]2015-11-04
Bugzilla
CVE-2015-7805 audacity: libsndfile: Heap overflow vulnerability when parsing specially crafted AIFF header [fedora-all]2015-11-04
Bugzilla
CVE-2015-7805 jack-audio-connection-kit: libsndfile: Heap overflow vulnerability when parsing specially crafted AIFF header [fedora-all]2015-11-04