Ubuntu Security Notice 849-1 – Tobias Klein discovered a heap-based buffer overflow in libsndfile. If a user or automated system processed a crafted VOC file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. Erik de Castro Lopo discovered a similar heap-based buffer overflow when processing AIFF files. If a user or automated system processed a crafted AIFF file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/82041/USN-849-1.txt
Source: https://packetstormsecurity.com/files/82041/Ubuntu-Security-Notice-849-1.html