Secunia Research has discovered a vulnerability in libsndfile, which can be exploited by malicious people to compromise an application using the library. The vulnerability is caused due to an integer overflow error in the processing of CAF description chunks. This can be exploited to cause a heap-based buffer overflow by tricking the user into processing a specially crafted CAF audio file. Successful exploitation may allow execution of arbitrary code. Version 1.0.18 of libsndfile is affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/75350/secunia-libsndfile.txt
Source: https://packetstormsecurity.com/files/75350/Secunia-libsndfile-Integer-Overflow.html