CVE-2024-50612: Medium severity libsndfile vulnerability
Published Oct 27, 2024
·Updated
Last updated 25 February 2025
Other sources
libsndfile through 1.2.2 has an oggvorbis.c vorbisanalysiswrote out-of-bounds read.
— MITRE
Affected Software
2 affected componentsFixes available
Libsndfile Project Libsndfile<=1.2.2
debian/libsndfile<=1.0.31-2, <=1.2.0-1
1.2.2-2
Event History
Oct 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via Red Hat·11:01 PM
DescriptionSeverityAffected Software
Feb 26, 2025
Data Sourced
via Ubuntu·12:11 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-50612?
CVE-2024-50612 has been classified as a moderate severity vulnerability due to its potential for causing an out-of-bounds read.
2
How do I fix CVE-2024-50612?
To fix CVE-2024-50612, you should upgrade to the latest version of libsndfile that is higher than 1.2.2.
3
What versions of libsndfile are affected by CVE-2024-50612?
CVE-2024-50612 affects all versions of libsndfile up to and including version 1.2.2.
4
What type of vulnerability is CVE-2024-50612?
CVE-2024-50612 is an out-of-bounds read vulnerability found in the ogg_vorbis.c file of libsndfile.
5
Is there a proof of concept available for CVE-2024-50612?
There is no officially published proof of concept for CVE-2024-50612, but discussions can be found in related issue trackers.