6.5
CVSSv3

CVE-2022-24599

Published: 24/02/2022 Updated: 28/12/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an malicious user to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

audio file library project audio file library 0.3.6

debian debian linux 10.0

fedoraproject fedora 37

fedoraproject fedora 38

fedoraproject fedora 39

Vendor Advisories

Debian Bug report logs - #1008017 audiofile: CVE-2022-24599 Package: src:audiofile; Maintainer for src:audiofile is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 20 Mar 2022 15:36:01 UTC Severity: important Tags: security, upstream ...
In autofile Audio File Library 036, there exists one memory leak vulnerability in printfileinfo, in printinfoc, which allows an attacker to leak sensitive information via a crafted file The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data (CVE-2022-24599) ...
In autofile Audio File Library 036, there exists one memory leak vulnerability in printfileinfo, in printinfoc, which allows an attacker to leak sensitive information via a crafted file The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data ...