CVE-2022-24599
MEDIUMAutofile Audio File Library 0.3.6 - Info Disclosure
Title source: llmDescription
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
References (6)
Scores
CVSS v3
6.5
EPSS
0.0022
EPSS Percentile
44.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Classification
CWE
CWE-401
Status
published
Affected Products (5)
audiofile/audiofile
debian/debian_linux
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
Timeline
Published
Feb 24, 2022
Tracked Since
Feb 18, 2026