PoC Index

CVE-2022-24599

MEDIUM 6.5EPSS 1.7%

In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
1.73% chance of exploitation in the next 30 days, 76th percentile
Published
2022-02-22
Updated
2025-11-03

Proof-of-concept exploits (1)

References

Related