CVE-2022-33065: [CVE-2026-37555] libsndfile IMA-ADPCM integer overflow (incomplete fix for CVE-2022-33065)
CVE-2022-33065[0]: | Multiple signed integers overflow in function aureadheader in | src/au.c and in functions mat4open and mat4readheader in | src/mat4.c in Libsndfile, allows an attacker to cause Denial of | Service or other unspecified impacts.
https://github.com/libsndfile/libsndfile/issues/833 https://github.com/libsndfile/libsndfile/issues/789
Other sources
Multiple signed integers overflow in function aureadheader in src/au.c and in functions mat4open and mat4readheader in src/mat4.c in Libsndfile allows an attacker to cause Denial of Service or other unspecified impacts.
— Microsoft
Multiple signed integers overflow in function aureadheader in src/au.c and in functions mat4open and mat4readheader in src/mat4.c in Libsndfile, allows an attacker to cause Denial of Service or other unspecified impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-33065?
The severity of CVE-2022-33065 is classified as high due to potential denial of service conditions.
How do I fix CVE-2022-33065?
To fix CVE-2022-33065, you should update to the latest version of the Libsndfile library that addresses this vulnerability.
What software is affected by CVE-2022-33065?
CVE-2022-33065 affects the Libsndfile library, specifically the versions that contain the vulnerable code.
What are the potential impacts of CVE-2022-33065?
The potential impacts of CVE-2022-33065 include denial of service and other unspecified vulnerabilities.
Is CVE-2022-33065 exploitable remotely?
Yes, CVE-2022-33065 is exploitable remotely, allowing an attacker to trigger the vulnerability from outside the affected system.