In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/mpruett/audiofile/issues/54 | third party advisory exploit |
https://lists.debian.org/debian-lts-announce/2023/11/msg00006.html | mailing list |