Summary
The remote host is missing an update to libsndfile announced via advisory DSA 2288-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202288-1
Insight
Hossein Lotfi discovered an integer overflow in libsndfile's code to parse Paris Audio files, which could potentially lead to the execution of arbitrary code.
For the oldstable distribution (lenny), this problem has been fixed in version 1.0.17-4+lenny3.
For the stable distribution (squeeze), this problem has been fixed in version 1.0.21-3+squeeze1
For the unstable distribution (sid), this problem has been fixed in version 1.0.25-1.
We recommend that you upgrade your libsndfile packages.
Severity
Classification
-
CVE CVE-2011-2696 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities