{"id":"CVE-2012-6303","details":"Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.","modified":"2026-04-10T03:42:34.565602Z","published":"2013-10-28T22:55:03Z","related":["openSUSE-SU-2024:11390-1"],"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00034.html"},{"type":"ADVISORY","url":"http://secunia.com/advisories/49889"},{"type":"ADVISORY","url":"http://security.gentoo.org/glsa/glsa-201309-04.xml"},{"type":"ADVISORY","url":"http://www.exploit-db.com/exploits/19772"},{"type":"ADVISORY","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2013:126"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2012/12/10/2"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2012/12/10/2"},{"type":"EVIDENCE","url":"http://www.exploit-db.com/exploits/19772"}],"schema_version":"1.7.5"}