CVE-2022-24599
24.02.2022, 15:15
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| audiofile | audiofile | 0.3.6 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| audiofile |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| audiofile |
| ||||||||||||||||
| audiofile-devel |
| ||||||||||||||||
| libaudiofile1 |
| ||||||||||||||||
| libaudiofile1-32bit |
|
Common Weakness Enumeration
References