VYPR
Unrated severityNVD Advisory· Published Sep 19, 2007· Updated Apr 23, 2026

CVE-2007-4974

CVE-2007-4974

Description

Heap-based buffer overflow in the flac_buffer_copy function in libsndfile 1.0.17 and earlier might allow remote attackers to execute arbitrary code via a FLAC file with crafted PCM data containing a block with a size that exceeds the previous block size.

Affected products

14
  • cpe:2.3:a:mega-nerd:libsndfile:*:*:*:*:*:*:*:*+ 13 more
    • cpe:2.3:a:mega-nerd:libsndfile:*:*:*:*:*:*:*:*range: <=1.0.17
    • cpe:2.3:a:mega-nerd:libsndfile:0.0.28:*:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:0.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.0:rc6:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mega-nerd:libsndfile:1.0.16:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

17

News mentions

0

No linked articles in our index yet.