CVE-2009-0186: libsndfile: overflows may lead to execution of arbitrary code

Severity: Critical

CVSS Score: 9.3

Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.