ALAS2-2020-1501 --- audiofileID: oval:org.secpod.oval:def:1700455 | Date: (C)2020-11-05 (M)2023-12-20 |
Class: PATCH | Family: unix |
The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert. An issue has been discovered in mpruett Audio File Library 0.3.6. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert