Referenced CVEs:
CVE-2009-1788, CVE-2009-1791
Description:
===========================================================Ubuntu Security Notice USN-849-1 October 15, 2009libsndfile vulnerabilitiesCVE-2009-1788, CVE-2009-1791===========================================================A security issue affects the following Ubuntu releases:Ubuntu 8.04 LTSUbuntu 8.10Ubuntu 9.04This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 8.04 LTS: libsndfile1 1.0.17-4ubuntu0.8.04.2Ubuntu 8.10: libsndfile1 1.0.17-4ubuntu0.8.10.2Ubuntu 9.04: libsndfile1 1.0.17-4ubuntu1.1After a standard system upgrade you need to restart your session to effectthe necessary changes.Details follow:Tobias Klein discovered a heap-based buffer overflow in libsndfile. If auser or automated system processed a crafted VOC file, an attacker couldcause a denial of service via application crash, or possibly executearbitrary code with the privileges of the user invoking the program.(CVE-2009-1788)Erik de Castro Lopo discovered a similar heap-based buffer overflow whenprocessing AIFF files. If a user or automated system processed a craftedAIFF file, an attacker could cause a denial of service via applicationcrash, or possibly execute arbitrary code with the privileges of the userinvoking the program. (CVE-2009-1791)
More...