Skip to content

The ChucK project includes code associated with a known vulnerability (CVE). #503

@mariamarutunian

Description

@mariamarutunian

A vulnerability identified as CVE-2014-9756 was discovered and fixed in libsndfile project with the following commit: libsndfile/libsndfile@725c7db. Which amended the "psf_fwrite" function located in src/file_io.c file.
ChucK project contains an identical "psf_fwrite" function in the src/core/util_sndfile.c file, which has not been fixed.

The bug was reported by a tool developed by the CAST: Static Analysis team during the DevHacks hackathon.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions