CVE-2015-7805 describes a critical heap-based buffer overflow vulnerability in libsndfile version 1.0.25, affecting products like mega-nerd libsndfile and openSUSE. This flaw allows remote attackers to achieve unspecified but potentially severe impact by manipulating the headindex value within an AIFF file. With a CVSS score of 9.3, this vulnerability is highly severe, indicating a network-based attack with medium complexity that could lead to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking widespread community discussion or media coverage, a local heap overflow exploit (EDB-38447) is publicly available, suggesting potential for exploitation despite no evidence of active widespread attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
1.0.25CPE matchmatch criteria | cpe:2.3:a:mega-nerd:libsndfile:1.0.25:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.