LOW · 2.1

CVE-2014-9496

The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.

Vulnerability Description

The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
Libsndfile ProjectLibsndfile< 1.0.26
OpensuseOpensuse13.1
DebianDebian Linux9.0
CanonicalUbuntu Linux12.04
OracleSolaris11.2

References

FAQ

What is CVE-2014-9496?

CVE-2014-9496 is a vulnerability with a CVSS score of 2.1 (LOW). The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.

How severe is CVE-2014-9496?

CVE-2014-9496 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-9496?

Check the references section above for vendor advisories and patch information. Affected products include: Libsndfile Project Libsndfile, Opensuse Opensuse, Debian Debian Linux, Canonical Ubuntu Linux, Oracle Solaris.