Debian Security Advisory
DSA-2288-1 libsndfile -- integer overflow
- Date Reported:
- 28 Jul 2011
- Affected Packages:
- libsndfile
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2011-2696.
- More information:
-
Hossein Lotfi discovered an integer overflow in libsndfile's code to parse Paris Audio files, which could potentially lead to the execution of arbitrary code.
For the oldstable distribution (lenny), this problem has been fixed in version 1.0.17-4+lenny3.
For the stable distribution (squeeze), this problem has been fixed in version 1.0.21-3+squeeze1
For the unstable distribution (sid), this problem has been fixed in version 1.0.25-1.
We recommend that you upgrade your libsndfile packages.