PT-2020-9984 · Unknown · Bass Audio Library

Published

2020-10-16

·

Updated

2020-10-27

·

CVE-2019-18794

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: BASS Audio Library version 2.4.14
Description: The issue is related to a Use after Free vulnerability in the BASS StreamCreateFile function when handling crafted .ogg files. This can be exploited by an attacker to gain access to sensitive information, potentially aiding in further attacks. If the exploitation attempt fails, it may result in a denial of service.
Recommendations: For BASS Audio Library version 2.4.14, consider avoiding the use of the BASS StreamCreateFile function with .ogg files until a fix is available. As a temporary workaround, restrict the handling of .ogg files to minimize the risk of exploitation.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18794

Affected Products

Bass Audio Library