cbcvebase.

Debian Libsndfile vulnerabilities

34 known vulnerabilities affecting debian/libsndfile.

Total CVEs
34
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5MEDIUM17LOW10

Vulnerabilities

Page 2 of 2
CVE-2018-19661P4LOWCVSS 6.5fixed in libsndfile 1.0.28-5 (bookworm)2018
CVE-2018-19661 [MEDIUM] CVE-2018-19661: libsndfile - An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the... An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service. Scope: local bookworm: resolved (fixed in 1.0.28-5) bullseye: resolved (fixed in 1.0.28-5) forky: resolved (fixed in 1.0.28-5) sid: resolved (fixed in 1.0.28-5) trixie: resolved (fixed in 1.0.28-5)
debian
CVE-2017-16942P4MEDIUMCVSS 6.5fixed in libsndfile 1.0.27-1 (bookworm)2017
CVE-2017-16942 [MEDIUM] CVE-2017-16942: libsndfile - In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the fun... In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the function wav_w64_read_fmt_chunk() in wav_w64.c, which may lead to DoS when playing a crafted audio file. Scope: local bookworm: resolved (fixed in 1.0.27-1) bullseye: resolved (fixed in 1.0.27-1) forky: resolved (fixed in 1.0.27-1) sid: resolved (fixed in 1.0.27-1) trixie: resolved (fi
debian
CVE-2017-8365P4MEDIUMCVSS 6.5fixed in libsndfile 1.0.27-3 (bookworm)2017
CVE-2017-8365 [MEDIUM] CVE-2017-8365: libsndfile - The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers t... The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file. Scope: local bookworm: resolved (fixed in 1.0.27-3) bullseye: resolved (fixed in 1.0.27-3) forky: resolved (fixed in 1.0.27-3) sid: resolved (fixed in 1.0.27-3) trixie: resolved (fixed in 1.
debian
CVE-2017-8362P4MEDIUMCVSS 6.5fixed in libsndfile 1.0.27-3 (bookworm)2017
CVE-2017-8362 [MEDIUM] CVE-2017-8362: libsndfile - The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attac... The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file. Scope: local bookworm: resolved (fixed in 1.0.27-3) bullseye: resolved (fixed in 1.0.27-3) forky: resolved (fixed in 1.0.27-3) sid: resolved (fixed in 1.0.27-3) trixie: resolved (fixed in
debian
CVE-2025-56226P4MEDIUMCVSS 5.3fixed in libsndfile 1.2.2-4 (forky)2025
CVE-2025-56226 [MEDIUM] CVE-2025-56226: libsndfile - Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_i... Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file. Scope: local bookworm: open bullseye: resolved forky: resolved (fixed in 1.2.2-4) sid: resolved (fixed in 1.2.2-4) trixie: resolved (fixed in 1.2.2-2+deb13u1)
debian
CVE-2017-7585P4MEDIUMCVSS 5.5fixed in libsndfile 1.0.27-2 (bookworm)2017
CVE-2017-7585 [MEDIUM] CVE-2017-7585: libsndfile - In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac... In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file. Scope: local bookworm: resolved (fixed in 1.0.27-2) bullseye: resolved (fixed in 1.0.27-2) forky: resolved (fixed in 1.0.27-2) sid: resolved (fixed in 1.0.27-2) trixie: resolved (fixed in 1.
debian
CVE-2017-7586P4MEDIUMCVSS 5.5fixed in libsndfile 1.0.27-2 (bookworm)2017
CVE-2017-7586 [MEDIUM] CVE-2017-7586: libsndfile - In libsndfile before 1.0.28, an error in the "header_read()" function (common.c)... In libsndfile before 1.0.28, an error in the "header_read()" function (common.c) when handling ID3 tags can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file. Scope: local bookworm: resolved (fixed in 1.0.27-2) bullseye: resolved (fixed in 1.0.27-2) forky: resolved (fixed in 1.0.27-2) sid: resolved (fixed in 1.0.27-2) trixie: r
debian
CVE-2014-9756P4MEDIUMCVSS 5.0fixed in libsndfile 1.0.25-10 (bookworm)2014
CVE-2014-9756 [MEDIUM] CVE-2014-9756: libsndfile - The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a d... The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable. Scope: local bookworm: resolved (fixed in 1.0.25-10) bullseye: resolved (fixed in 1.0.25-10) forky: resolved (fixed in 1.0.25-10) sid: resolved (fixed in 1.0.25-10)
debian
CVE-2017-7741P4MEDIUMCVSS 5.5fixed in libsndfile 1.0.27-2 (bookworm)2017
CVE-2017-7741 [MEDIUM] CVE-2017-7741: libsndfile - In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac... In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585. Scope: local bookworm: resolved (fixed in 1.0.27-2) bullseye: resolved (fixed in 1.0.27-2) forky: resolved (
debian
CVE-2017-7742P4MEDIUMCVSS 5.5fixed in libsndfile 1.0.27-3 (bookworm)2017
CVE-2017-7742 [MEDIUM] CVE-2017-7742: libsndfile - In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac... In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with read memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585. Scope: local bookworm: resolved (fixed in 1.0.27-3) bullseye: resolved (fixed in 1.0.27-3) forky: resolved (f
debian
CVE-2024-50612P4MEDIUMCVSS 5.5fixed in libsndfile 1.2.0-1+deb12u1 (bookworm)2024
CVE-2024-50612 [MEDIUM] CVE-2024-50612: libsndfile - libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds... libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read. Scope: local bookworm: resolved (fixed in 1.2.0-1+deb12u1) bullseye: resolved (fixed in 1.0.31-2+deb11u1) forky: resolved (fixed in 1.2.2-2) sid: resolved (fixed in 1.2.2-2) trixie: resolved (fixed in 1.2.2-2)
debian
CVE-2019-3832P4MEDIUMCVSS 6.5fixed in libsndfile 1.0.28-6 (bookworm)2019
CVE-2019-3832 [MEDIUM] CVE-2019-3832: libsndfile - It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and s... It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash. Scope: local bookworm: resolved (fixed in 1.0.28-6) bullseye: resolved (fixed in 1.0.28-6) forky: resolved (fixed in 1.0.28-6) si
debian
CVE-2009-4835P4LOWCVSS 4.3fixed in libsndfile 1.0.21-3 (bookworm)2009
CVE-2009-4835 [MEDIUM] CVE-2009-4835: libsndfile - The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32... The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions in libsndfile 1.0.20 allow context-dependent attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted audio file. Scope: local bookworm: resolved (fixed in 1.0.21-3) bullseye: resolved (fixed in 1.0.21-3
debian
CVE-2014-9496P4LOWCVSS 2.1fixed in libsndfile 1.0.25-9.1 (bookworm)2014
CVE-2014-9496 [LOW] CVE-2014-9496: libsndfile - The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have... The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read. Scope: local bookworm: resolved (fixed in 1.0.25-9.1) bullseye: resolved (fixed in 1.0.25-9.1) forky: resolved (fixed in 1.0.25-9.1) sid: resolved (fixed in 1.0.25-9.1) t
debian
Debian Libsndfile vulnerabilities | cvebase