REDHAT-BUG-2322057: Medium severity libsndfile vulnerability
Published Oct 27, 2024
·Updated
libsndfile through 1.2.2 has an oggvorbis.c vorbisanalysiswrote out-of-bounds read.
Affected Software
1 affected component
libsndfile libsndfile<=1.2.2
Event History
Oct 27, 2024
Data Sourced
via Red Hat·11:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2322057?
The severity of REDHAT-BUG-2322057 is likely high due to the potential for out-of-bounds memory access leading to local denial of service or remote code execution.
2
How do I fix REDHAT-BUG-2322057?
To fix REDHAT-BUG-2322057, you should upgrade libsndfile to the latest version that addresses the vulnerability.
3
Which versions of libsndfile are affected by REDHAT-BUG-2322057?
Versions of libsndfile up to and including 1.2.2 are affected by REDHAT-BUG-2322057.
4
Is there a workaround for REDHAT-BUG-2322057?
Currently, there is no known workaround for REDHAT-BUG-2322057; the recommended action is to apply the security update.
5
What causes the vulnerability in REDHAT-BUG-2322057?
The vulnerability in REDHAT-BUG-2322057 is caused by an out-of-bounds read in the vorbis_analysis_wrote function of ogg_vorbis.c.