First published: Thu Feb 13 2025(Updated: )
It was discovered that libsndfile incorrectly handled certain malformed OggVorbis files. An attacker could possibly use this issue to cause libsndfile to crash, resulting in a denial of service.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libsndfile1 | <1.0.25-10ubuntu0.16.04.3+esm4 | 1.0.25-10ubuntu0.16.04.3+esm4 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/sndfile-programs | <1.0.25-10ubuntu0.16.04.3+esm4 | 1.0.25-10ubuntu0.16.04.3+esm4 |
Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7267-1 is considered high due to the potential for denial of service caused by malformed OggVorbis files.
To fix the vulnerability USN-7267-1, update libsndfile1 and sndfile-programs to version 1.0.25-10ubuntu0.16.04.3+esm4.
Ubuntu 16.04 is the only version affected by USN-7267-1.
The issue in USN-7267-1 is that libsndfile incorrectly handles certain malformed OggVorbis files, leading to crashes.
While USN-7267-1 can cause a denial of service, it does not indicate a direct remote attack vector, but it may be exploited to crash services.