Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.
| Software | From | Fixed in |
|---|---|---|
| bladeenc / bladeenc | 0.94.0 | 0.94.0.x |
| bladeenc / bladeenc | 0.93.10 | 0.93.10.x |
| bladeenc / bladeenc | 0.94.2 | 0.94.2.x |
| bladeenc / bladeenc | 0.94.1 | 0.94.1.x |
| bladeenc / bladeenc | 0.92.7 | 0.92.7.x |