Mandriva Linux Security Advisory : snack (MDVSA-2013:126)
Medium Nessus Plugin ID 66138
SynopsisThe remote Mandriva Linux host is missing one or more security updates.
DescriptionUpdated snack packages fix security vulnerability :
Two vulnerabilities have been discovered in Snack Sound Toolkit, which are caused due to missing boundary checks in the GetWavHeader() function (generic/jkSoundFile.c) when parsing either format sub-chunks or unknown sub-chunks. This can be exploited to cause a heap-based buffer overflow via specially crafted WAV files with overly large chunk sizes specified (CVE-2012-6303).
SolutionUpdate the affected python-snack and / or tcl-snack packages.