发布时间: 2022年5月28日
修改时间: 2024年10月31日
An out-of-bounds read flaw was found in libsndfile s FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.
NVD | openEuler | |
---|---|---|
Confidentiality | Low | High |
Attack Vector | Network | Network |
CVSS评分 | 7.1 | 8.1 |
Attack Complexity | Low | Low |
Privileges Required | None | None |
Scope | Unchanged | Unchanged |
Integrity | None | None |
User Interaction | Required | Required |
Availability | High | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2022-1481 | libsndfile security update | 2022年5月28日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | libsndfile | Fixed |
KY3.4-5A | libsndfile | Fixed |
KY3.5.1 | libsndfile | Fixed |