Back

libsndfile: Out of bounds memory access in psf_strlcpy_crlf

Published Nov 6, 2015

Description

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

Affected products

Remediation

Red Hat statement

This CVE has been rejected upstream after analysis showed the issue originated from a flawed test case, not a real vulnerability. The test incorrectly passed sizeof(src)—a pointer size—causing false out-of-bounds warnings under AddressSanitizer. The test runs only during make check and has no impact on production. Vendor fixes also reflect the test's invalidity, confirming no security risk exists. Refer to the announcement mail here: https://seclists.org/oss-sec/2015/q4/226. If you have additional information or concerns regarding this determination, please contact Red Hat Product Security for further clarification.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Nov 6, 2015
Updated n/a
Reserved n/a
NVD
Status Rejected
Modified Nov 7, 2023
Red Hat
Severity Low
Public date Jul 10, 2015