Bug#860255: libsndfile: CVE-2017-7742: Invalid memory read in flac_buffer_copy function

2017-04-13 Thread Salvatore Bonaccorso
For reference in the Debian BTS: ==15547== Memcheck, a memory error detector ==15547== Copyright (C) 2002-2015, and GNU GPL'd, by Julian Seward et al. ==15547== Using Valgrind-3.12.0 and LibVEX; rerun with -h for copyright info ==15547== Command: sndfile-resample -to 24000 -c 1 /root/poc/00260-li

Bug#860255: libsndfile: CVE-2017-7742: Invalid memory read in flac_buffer_copy function

2017-04-13 Thread Salvatore Bonaccorso
Source: libsndfile Version: 1.0.27-1 Severity: important Tags: security upstream Control: found -1 1.0.27-2 Hi, the following vulnerability was published for libsndfile. CVE-2017-7742[0]: | In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" | function (flac.c) can be exploited to