Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 320949 (CVE-2009-4835) - media-libs/libsndfile: DOS (CVE-2009-4835)
Summary: media-libs/libsndfile: DOS (CVE-2009-4835)
Status: RESOLVED FIXED
Alias: CVE-2009-4835
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://bugs.debian.org/cgi-bin/bugrep...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2010-05-21 21:34 UTC by Stefan Behte (RETIRED)
Modified: 2010-08-01 13:34 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2010-05-21 21:34:33 UTC
CVE-2009-4835 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4835):
  The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init,
  (5) float32_init, and (6) sds_read_header functions in libsndfile
  1.0.20 allow context-dependent attackers to cause a denial of service
  (divide-by-zero error and application crash) via a crafted audio file.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2010-08-01 13:34:14 UTC
DOS in client app -> closing noglsa.