Logo
vulnerabilityCVE-2022-24599
Name
CVE-2022-24599
Source
NVD ( link)Debian ( link)
Description
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
audiofile
Exploitable

Vulnerability Ratings#


6.5
CVSSv31
4.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
0.3.6
Exploitable
yocto
scarthgap
0.3.6
Exploitable