vendor:
libao
by:
qflb.wu
5,5
CVSS
MEDIUM
Memory Corruption
119
CWE
Product Name: libao
Affected Version From: 1.2.0
Affected Version To: 1.2.0
Patch Exists: YES
Related CWE: CVE-2017-11548
CPE: a:xiph.org:libao:1.2.0
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
libao memory corruption vulnerability
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 can cause a denial of service(memory corruption) via a crafted mp3 file. I found this bug when I test mpg321 0.3.2 which used the libao library.
Mitigation:
Update to the latest version of libao library.