Back to Database
Status published
Low
CVE-2014-9496
The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to...
Vulnerability Description
The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9496
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/71796
- https://github.com/erikd/libsndfile/issues/93
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00016.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:024
- https://github.com/erikd/libsndfile/commit/dbe14f00030af5d3577f4cabbf9861db59e9c378
- http://www.ubuntu.com/usn/USN-2832-1
- http://secunia.com/advisories/62320
- https://security.gentoo.org/glsa/201612-03
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://advisories.mageia.org/MGASA-2015-0015.html
- http://www.openwall.com/lists/oss-security/2015/01/04/4
- https://seclists.org/bugtraq/2019/Apr/23
More from libsndfile project
View All →CVE-2022-33065
Multiple signed integers overflow in function au_read_header in src/au.c and...
High
7.8
CVE-2022-33064
An off-by-one error in function wav_read_header in src/wav.c in Libsndfile...
High
7.8
CVE-2021-3246
A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30...
High
8.8
CVE-2018-19758
There is a heap-based buffer over-read at wav.c in wav_write_header...
Medium
6.5
CVE-2018-19662
An issue was discovered in libsndfile 1.0.28. There is a...
High
8.1
Affected Vendor
libsndfile project
View all reports →Affected Software
libsndfile, opensuse, debian linux, ubuntu linux, solaris
Vulnerable Versions:
0, 13.1, 13.2, 9.0, 12.04, 14.04, 15.04, 15.10, 11.2
Timeline
Official Publish:
January 16th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.