The updated packages fix a security vulnerability In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo . MGASA-2023-0336 - Updated audiofile packages fix a security vulnerability Publication date: 04 Dec 2023 URL: https://advisories.mageia.org/MGASA-2023-0336.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-24599 The updated packages fix a security vulnerability In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data. (CVE-2022-24599) References: - https://bugs.mageia.org/show_bug.cgi?id=32561 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.