Wind River Support Network

HomeDefectsLIN1021-6098
Acknowledged

LIN1021-6098 : Security Advisory - libsndfile1 - CVE-2022-33064

Created: Jul 20, 2023    Updated: Jul 21, 2023
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Service or other unspecified impacts.

CREATE(Triage):(User=admin) CVE-2022-33064 (https://nvd.nist.gov/vuln/detail/CVE-2022-33064)
Live chat
Online