ubuntu · CVE-2011-2696

Quick triage

Priority: medium Published: 2011-07-21 00:00:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2011-2696 medium priority: Ubuntu including 1 source packages (libsndfile), 5 status rows across 5 suites (hardy, lucid, maverick, natty, upstream): released 4, ignored 1.

Description:

Integer overflow in libsndfile before 1.0.25 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio Format (PAF) file that triggers a heap-based buffer overflow.

cvelogic Threat Intelligence