In libsndfile version 1.0.28, an error in the "aiffreadchanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.0.28"
}
]
}