6.5

CVE-2024-33431

Exploit
An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via a crafted .wav file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
StsazPhiola Version2.0 Updaterc22
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.89% 0.546
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CWE-670 Always-Incorrect Control Flow Implementation

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

https://github.com/stsaz/phiola/
Product
https://github.com/Helson-S/FuzzyTesting/blob/master/phiola/flowPointException-1/flowPointException-1.assets/image-20240420004701828.png
Exploit
https://github.com/Helson-S/FuzzyTesting/blob/master/phiola/flowPointException-1/flowPointException-1.md
Exploit
https://github.com/Helson-S/FuzzyTesting/blob/master/phiola/flowPointException-1/poc/I0I72U~G
Exploit
https://github.com/Helson-S/FuzzyTesting/tree/master/phiola/flowPointException-1
Exploit
https://github.com/Helson-S/FuzzyTesting/tree/master/phiola/flowPointException-1/poc
Exploit
https://github.com/stsaz/phiola/issues/27
Vendor Advisory
Exploit
Issue Tracking