CVE-2016-2541: Buffer Overflow
Published Feb 7, 2018
·Updated
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.
Affected Software
1 affected component
Audacityteam Audacity<2.1.2
Event History
Feb 7, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2541?
CVE-2016-2541 has a low severity rating due to its potential for denial of service through memory corruption.
2
How do I fix CVE-2016-2541?
To fix CVE-2016-2541, upgrade to Audacity version 2.1.2 or later.
3
What type of attack does CVE-2016-2541 enable?
CVE-2016-2541 enables remote attackers to execute a denial of service attack that results in application crashes.
4
What versions of Audacity are affected by CVE-2016-2541?
Audacity versions prior to 2.1.2 are affected by CVE-2016-2541.
5
Is there a workaround for CVE-2016-2541?
The best workaround for CVE-2016-2541 is to avoid opening untrusted MP2 files in versions of Audacity prior to 2.1.2.