CVE-2022-24599

Name
CVE-2022-24599
Description
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/mpruett/audiofile/issues/60
https://lists.debian.org/debian-lts-announce/2023/11/msg00006.html
Mailing List https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N4JXZ6QAMA3TSRY6GUZRY3WTHR7P5TPH/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WTETOUJNRR75REYJZTBGF6TAJZYTMXUY/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZPG27YKICLIWUFOPVUOAFAZGOX4BNHY/
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/07/msg00020.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:audio_file_library_project:audio_file_library:0.3.6:*:*:*:*:*:*:* audio_file_library == None == 0.3.6
cpe:2.3:a:audiofile:audiofile:0.3.6:*:*:*:*:*:*:* audiofile == None == 0.3.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
audiofile edge-community 0.3.6-r3 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
audiofile 3.23-community 0.3.6-r3 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
audiofile 3.22-community 0.3.6-r3 Bart Ribbers <bribbers@disroot.org> possibly vulnerable