In pvmp3_get_main_data_size of pvmp3_get_main_data_size...
High severity
Unreviewed
Published
Nov 27, 2024
to the GitHub Advisory Database
•
Updated Nov 30, 2024
Description
Published by the National Vulnerability Database
Nov 27, 2024
Published to the GitHub Advisory Database
Nov 27, 2024
Last updated
Nov 30, 2024
In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lead to remote information disclosure of global static variables with no additional execution privileges needed. User interaction is not needed for exploitation.
References