Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.226
                        
                    
                    
                        
                            EPSS Ranking 95.6%