FluidSynth 2.1.7 contains a use after free vulnerability in sfloader/fluid_sffile.c that can result in arbitrary code execution or a denial of service (DoS) if a malicious soundfont2 file is loaded into a fluidsynth library.
References
| Link | Resource |
|---|---|
| https://github.com/FluidSynth/fluidsynth/issues/808 | Exploit Third Party Advisory |
| https://github.com/FluidSynth/fluidsynth/pull/810 | Third Party Advisory |
Configurations
Information
Published : 2021-04-13 14:15
Updated : 2021-06-30 01:15
NVD link : CVE-2021-28421
Mitre link : CVE-2021-28421
JSON object : View
Products Affected
fluidsynth
- fluidsynth
CWE
CWE-416
Use After Free
