CVE-2021-28421

FluidSynth 2.1.7 contains a use after free vulnerability in sfloader/fluid_sffile.c that can result in arbitrary code execution or a denial of service (DoS) if a malicious soundfont2 file is loaded into a fluidsynth library.
References
Link Resource
https://github.com/FluidSynth/fluidsynth/issues/808 Exploit Third Party Advisory
https://github.com/FluidSynth/fluidsynth/pull/810 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:fluidsynth:fluidsynth:2.1.7:*:*:*:*:*:*:*

Information

Published : 2021-04-13 14:15

Updated : 2021-06-30 01:15


NVD link : CVE-2021-28421

Mitre link : CVE-2021-28421


JSON object : View

Products Affected

fluidsynth

  • fluidsynth
CWE
CWE-416

Use After Free