CVE-2011-2696

Publication date 21 July 2011

Last updated 24 July 2024


Ubuntu priority

Description

Integer overflow in libsndfile before 1.0.25 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio Format (PAF) file that triggers a heap-based buffer overflow.

Read the notes from the security team

Status

Package Ubuntu Release Status
libsndfile 11.04 natty
Fixed 1.0.23-1ubuntu0.1
10.10 maverick
Fixed 1.0.21-2ubuntu0.10.10.1
10.04 LTS lucid
Fixed 1.0.21-2ubuntu0.10.04.1
8.04 LTS hardy Ignored end of life

Notes


jdstrand

bzr branch http://www.mega-nerd.com/Bzr/libsndfile-dev/

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libsndfile

References

Related Ubuntu Security Notices (USN)

    • USN-1174-1
    • libsndfile vulnerability
    • 25 July 2011

Other references