Versions mentioned in the description apply to the upstream
Remediation section below for
Debian:9 relevant versions.
A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.
libsndfile to version 1.0.27-3+deb9u2 or higher.