Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://packetstormsecurity.com/files/140365/Audacity-2.1.2-DLL-Hijacking.html | vdb entry third party advisory |
https://github.com/GitHubAssessments/CVE_Assessments_10_2019 | third party advisory |