Related Vulnerabilities: CVE-2022-24599  

In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.

Description

The MITRE CVE dictionary describes this issue as:

In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.

Additional Information

  • Bugzilla 2058371: CVE-2022-24599 audiofile: memory leak in printinfo.c
  • FAQ: Frequently asked questions about CVE-2022-24599