ZeroHour

CVE-2022-24599

PoC
CVSS 3.1
6.5 medium
EPSS
2%p76
Published
()
Modified
Description

In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.

Vendors
audiofiledebianfedoraproject
Products
audiofile, debian linux, fedora
Weakness
CWE-401
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.