« List of all CVEs

CVE-2021-4156

Published: 3/23/2022 Last updated: 8/3/2024 Reserved: 12/22/2021

An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

conf-sndfile

Products affected (1)

Product Vendor Version
libsndfile n/a n/a

References (12)