In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
References
Link | Resource |
---|---|
https://github.com/mpruett/audiofile/issues/60 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2022-02-24 07:15
Updated : 2022-03-03 08:29
NVD link : CVE-2022-24599
Mitre link : CVE-2022-24599
JSON object : View
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
Products Affected
audio_file_library_project
- audio_file_library