Unrated severityNVD Advisory· Published Jul 27, 2011· Updated Apr 29, 2026
CVE-2011-2696
CVE-2011-2696
Description
Integer overflow in libsndfile before 1.0.25 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio Format (PAF) file that triggers a heap-based buffer overflow.
Affected products
29cpe:2.3:a:mega-nerd:libsndfile:*:*:*:*:*:*:*:*+ 28 more
- cpe:2.3:a:mega-nerd:libsndfile:*:*:*:*:*:*:*:*range: <=1.0.24
- cpe:2.3:a:mega-nerd:libsndfile:0.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:0.0.28:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.0:rc6:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.17:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.18:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.19:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.20:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.21:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.22:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.23:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
24- secunia.com/advisories/45125nvdVendor Advisory
- secunia.com/advisories/45351nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2011-July/062955.htmlnvd
- secunia.com/advisories/45384nvd
- secunia.com/advisories/45388nvd
- secunia.com/advisories/45433nvd
- www.debian.org/security/2011/dsa-2288nvd
- www.mandriva.com/security/advisoriesnvd
- www.mega-nerd.com/libsndfile/ChangeLognvd
- www.openwall.com/lists/oss-security/2011/07/14/1nvd
- www.openwall.com/lists/oss-security/2011/07/14/2nvd
- www.openwall.com/lists/oss-security/2011/07/14/3nvd
- www.openwall.com/lists/oss-security/2011/07/14/4nvd
- www.openwall.com/lists/oss-security/2011/07/15/1nvd
- www.openwall.com/lists/oss-security/2011/07/15/3nvd
- www.openwall.com/lists/oss-security/2011/07/15/4nvd
- www.openwall.com/lists/oss-security/2011/07/18/1nvd
- www.redhat.com/support/errata/RHSA-2011-1084.htmlnvd
- www.securelist.com/en/advisories/45125nvd
- www.securityfocus.com/bid/48644nvd
- www.ubuntu.com/usn/USN-1174-1nvd
- bugs.gentoo.org/show_bug.cginvd
- bugzilla.redhat.com/show_bug.cginvd
- hermes.opensuse.org/messages/10387521nvd
News mentions
0No linked articles in our index yet.