CVE-2022-24599: Medium severity audio file library vulnerability
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24599?
CVE-2022-24599 has been classified as a moderate severity vulnerability due to its potential to leak sensitive information.
How do I fix CVE-2022-24599?
To mitigate CVE-2022-24599, users should update to the fixed version 0.3.6-7 or later of the affected Audio File Library.
What software is affected by CVE-2022-24599?
CVE-2022-24599 affects Audio File Library version 0.3.6 and certain Debian and Fedora distributions.
What kind of information can be leaked through CVE-2022-24599?
CVE-2022-24599 can allow an attacker to leak sensitive information from the memory during the execution of the printfileinfo function.
Is there a specific platform where CVE-2022-24599 is a concern?
CVE-2022-24599 is particularly a concern for users of Debian 10 and Fedora versions 37, 38, and 39.