An out-of-bounds read flaw was found in libsndfile's FLAC codec...
Vulnerability Description
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-4156
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2027690
- https://github.com/libsndfile/libsndfile/pull/732/commits/4c30646abf7834e406f7e2429c70bc254e18beab
- https://github.com/libsndfile/libsndfile/issues/731
- https://lists.debian.org/debian-lts-announce/2022/06/msg00020.html
- https://lists.debian.org/debian-lts-announce/2022/09/msg00036.html
- https://security.gentoo.org/glsa/202309-11