[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4402-1] libsndfile security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4402-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                   Bastien Roucariès
December 11, 2025                             https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : libsndfile
Version        : 1.0.31-2+deb11u2
CVE ID         : CVE-2021-4156
Debian Bug     : 1014713

An out-of-bounds read flaw was found in libsndfile's
FLAC codec functionality. An attacker who is able to
submit a specially crafted file (via tricking a user
to open or otherwise) to an application linked with
libsndfile and using the FLAC codec, could trigger
an out-of-bounds read that would most likely cause
a crash but could potentially leak memory information
that could be used in further exploitation of other flaws.

For Debian 11 bullseye, this problem has been fixed in version
1.0.31-2+deb11u2.

We recommend that you upgrade your libsndfile packages.

For the detailed security status of libsndfile please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libsndfile

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmk6rHsACgkQADoaLapB
CF/AcBAAipMqN7KdqFanfQKSOKe9b9uUjlGQIdFL8fU+pY/XG2u6sjZwfAdqIqa3
nj6Y/gZy4WiIuAcp+qlaGoE8YFd1oBErv+vFk7YQjcTbKlA9VPZ85aQc3etim6Ju
H1Fcx+1iMkAHGGKeJPwV783hyXgcqPFlSUpU+fshTYMEmDkxiz5rh+beaiPLTVva
06k+tKez2WXZZUEAFw6RjtMLLe1YZl+wuBGLcGO20tfIyqn3Sk4JPrsR75yzTIrF
qrSCOvu9FU7Psbw9YQg8vX8Eqdwr8KSuXHf+iGwSXw5S23wvrIBo1YaDPV/92VgC
jRsTdvddlEgnIGQyoVf7gMNLGRz0f5BQPjOueN37z1H6dN1tjBLH52grur4SQGHU
f1c7dfsY1ZeHhge1Ny/7Tw+6aAsR1mWu9cKMPwmdaBbS0WW0oTeXdV1pMJ1xaeA5
syS22D/YAMrUOSSTLGN7fni4hPOnQEiLbkxDUvYC3Mb7AvASrsicZW+YmF1IAg0R
hvWJueoTQklbe9+FnvEEIRDeACjpIFA7b8DTDSbgn+9CPCpB/ud8be1kAhgD6nUb
arQv+WVPQBx9SrKze6Kp8177UNnbi/hzHtgZ9J15Z6Y648vu5W9zwEpUYnRo87Fy
wPXFz46HTmfj2s8OmKGSF8/lSsYBpXVMMqqDi3K9lIEut32Lx/o=
=B8ID
-----END PGP SIGNATURE-----


Reply to: