USN-7273-1: libsndfile vulnerabilities
It was discovered that libsndfile incorrectly handled memory when executing its FLAC codec. If a user or automated system were tricked into processing a specially crafted sound file, an attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2021-4156) It was discovered that libsndfile incorrectly handled certain malformed OggVorbis files. An attacker could possibly use this issue to cause libsndfile to crash, resulting in a denial of service. (CVE-2024-50612)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7273-1?
The severity of USN-7273-1 is categorized as high due to potential denial of service and information leakage risks.
What are the affected versions in USN-7273-1?
USN-7273-1 affects specific versions of libsndfile1 and sndfile-programs across various Ubuntu releases including 22.04, 20.04, 18.04, and 14.04.
How do I fix USN-7273-1?
To fix USN-7273-1, update to the recommended package versions mentioned in the advisory for your Ubuntu release.
What types of issues does USN-7273-1 address?
USN-7273-1 addresses vulnerabilities related to memory handling in the FLAC codec of libsndfile.
Can USN-7273-1 affect automated systems?
Yes, USN-7273-1 can impact automated systems if they process specially crafted sound files, leading to potential denial of service.