Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25491 | A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution. |
Thu, 11 Sep 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libsndfile Project
Libsndfile Project libsndfile |
|
| CPEs | cpe:2.3:a:libsndfile_project:libsndfile:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libsndfile Project
Libsndfile Project libsndfile |
Fri, 22 Aug 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | libsndfile: buffer overflow when processing crafted IRCAM audio files | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 21 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-121 | |
| Metrics |
cvssV3_1
|
Thu, 21 Aug 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-21T19:56:46.362Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-52194
Updated: 2025-08-21T19:56:24.144Z
Status : Analyzed
Published: 2025-08-21T15:15:33.110
Modified: 2025-09-11T18:17:03.153
Link: CVE-2025-52194
OpenCVE Enrichment
No data.
EUVD