CVE-2021-3246: Buffer Overflow
A heap buffer overflow vulnerability in msadpcmdecodeblock of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libsndfileto a version that resolves this vulnerability.Fixed in 1.0.28-6+deb10u1Fixed in 1.0.28-6+deb10u2Fixed in 1.0.31-2Fixed in 1.2.0-1Fixed in 1.2.2-1
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3246?
CVE-2021-3246 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2021-3246?
To fix CVE-2021-3246, users should upgrade to a patched version of libsndfile, such as 1.0.31 or later.
What component is affected by CVE-2021-3246?
CVE-2021-3246 affects the libsndfile library specifically in the msadpcm_decode_block function.
Which versions of libsndfile are vulnerable to CVE-2021-3246?
Versions of libsndfile prior to 1.0.31 and specifically version 1.0.30 are affected by CVE-2021-3246.
Is CVE-2021-3246 related to WAV files?
Yes, CVE-2021-3246 allows attackers to exploit the vulnerability through crafted WAV files.