CVE-2012-6303

Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
kthsnack_sound_toolkit
2.2.10
kthwavesurfer
1.8.8:p4
opensuseopensuse
13.1
opensuseopensuse
13.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
snack
bullseye
2.2.10.20090623-dfsg-10
fixed
bookworm
2.2.10.20090624+dfsg-1
fixed
sid
2.2.10.20090624+dfsg-2
fixed
trixie
2.2.10.20090624+dfsg-2
fixed
wavesurfer
bookworm
1.8.8p5-1.1
fixed
bullseye
1.8.8p5-1.1
fixed
sid
1.8.8p5-3
fixed
trixie
1.8.8p5-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
snack
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
not-affected
raring
ignored
quantal
ignored
precise
ignored
oneiric
ignored
lucid
ignored
hardy
ignored
wavesurfer
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
lucid
not-affected
hardy
not-affected