CVE-2022-24599
published 2022-02-24CVE-2022-24599: In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.73%
75.4th percentile
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| audiofile | audiofile | — | — |
| audiofile | audiofile | >= 0 < 0.3.6-5+deb11u1 | 0.3.6-5+deb11u1 |
| audiofile | audiofile | >= 0 < 0.3.6-5+deb12u1 | 0.3.6-5+deb12u1 |
| audiofile | audiofile | >= 0 < 0.3.6-6 | 0.3.6-6 |
| audiofile | audiofile | >= 0 < 0.3.6-6 | 0.3.6-6 |
| audiofile | audiofile | >= 0 < 0.3.6-5+deb10u1build0.20.04.1 | 0.3.6-5+deb10u1build0.20.04.1 |
| audiofile | audiofile | >= 0 < 0.3.6-5+deb10u1build0.22.04.1 | 0.3.6-5+deb10u1build0.22.04.1 |
| audiofile | audiofile | >= 0 < 0.3.6-2ubuntu0.14.04.3+esm1 | 0.3.6-2ubuntu0.14.04.3+esm1 |
| audiofile | audiofile | >= 0 < 0.3.6-2ubuntu0.16.04.1+esm1 | 0.3.6-2ubuntu0.16.04.1+esm1 |
| audiofile | audiofile | >= 0 < 0.3.6-4ubuntu0.1~esm1 | 0.3.6-4ubuntu0.1~esm1 |
| debian | audiofile | < audiofile 0.3.6-5+deb12u1 (bookworm) | audiofile 0.3.6-5+deb12u1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
audiofile vulnerabilities
osv·2023-12-14·CVSS 6.5
CVE-2018-13440 [MEDIUM] audiofile vulnerabilities
audiofile vulnerabilities
It was discovered that audiofile could be made to dereference invalid
memory. If a user or an automated system were tricked into opening a
specially crafted file, an attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2018-13440)
It was discovered that audiofile could be made to write out of bounds. If a
user or an automated system were tricked into opening a specially crafted
file, an attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected Ubuntu 16.04
LTS and Ubuntu 18.04 LTS. (CVE-2018-17095)
It was discovered that audiofile could be made to dereference invalid
memory. If a user or an automated system were tric
GHSA
GHSA-9hgh-v7v7-5f66: In autofile Audio File Library 0
ghsa_unreviewed·2022-02-25
CVE-2022-24599 [MEDIUM] CWE-401 GHSA-9hgh-v7v7-5f66: In autofile Audio File Library 0
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
OSV
CVE-2022-24599: In autofile Audio File Library 0
osv·2022-02-24·CVSS 6.5
CVE-2022-24599 [MEDIUM] CVE-2022-24599: In autofile Audio File Library 0
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
Ubuntu
audiofile vulnerabilities
vendor_ubuntu·2023-12-14·CVSS 6.5
CVE-2018-17095 [MEDIUM] audiofile vulnerabilities
Title: audiofile vulnerabilities
Summary: Several security issues were fixed in audiofile.
It was discovered that audiofile could be made to dereference invalid
memory. If a user or an automated system were tricked into opening a
specially crafted file, an attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2018-13440)
It was discovered that audiofile could be made to write out of bounds. If a
user or an automated system were tricked into opening a specially crafted
file, an attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected Ubuntu 16.04
LTS and Ubuntu 18.04 LTS. (CVE-2018-17095)
It was discovered that audiofile could be made to dere
Red Hat
audiofile: memory leak in printinfo.c
vendor_redhat·2022-02-24·CVSS 6.5
CVE-2022-24599 [MEDIUM] CWE-401 audiofile: memory leak in printinfo.c
audiofile: memory leak in printinfo.c
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
Package: audiofile (Red Hat Enterprise Linux 6) - Out of support scope
Package: audiofile (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2022-24599: audiofile - In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability...
vendor_debian·2022·CVSS 6.5
CVE-2022-24599 [MEDIUM] CVE-2022-24599: audiofile - In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability...
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
Scope: local
bookworm: resolved (fixed in 0.3.6-5+deb12u1)
bullseye: resolved (fixed in 0.3.6-5+deb11u1)
forky: resolved (fixed in 0.3.6-6)
sid: resolved (fixed in 0.3.6-6)
trixie: resolved (fixed in 0.3.6-6)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/mpruett/audiofile/issues/60https://lists.debian.org/debian-lts-announce/2023/11/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N4JXZ6QAMA3TSRY6GUZRY3WTHR7P5TPH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTETOUJNRR75REYJZTBGF6TAJZYTMXUY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZPG27YKICLIWUFOPVUOAFAZGOX4BNHY/https://github.com/mpruett/audiofile/issues/60https://lists.debian.org/debian-lts-announce/2023/11/msg00006.htmlhttps://lists.debian.org/debian-lts-announce/2025/07/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N4JXZ6QAMA3TSRY6GUZRY3WTHR7P5TPH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTETOUJNRR75REYJZTBGF6TAJZYTMXUY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZPG27YKICLIWUFOPVUOAFAZGOX4BNHY/
2022-02-24
Published