MediaArea MediaInfoLib
- 26.01
A heap-based buffer overflow vulnerability has been identified in the Channel Splitting feature of MediaArea MediaInfoLib version 26.01. This vulnerability allows for arbitrary code execution by exploiting the way the library processes multi-channel audio in RIFF files. When a specially crafted .riff file is parsed, the library can be tricked into overwriting memory, potentially leading to execution of attacker-controlled code.
Exploitation of this vulnerability can result in a heap-based buffer overflow, allowing for arbitrary code execution.
The vulnerability can be reproduced by using a .riff file that has more than 2 audio channels, a bit depth of 20 bits, and a sampling rate of 48000 Hz. When this file is processed by MediaInfoLib version 26.01, the channel splitting functionality will incorrectly handle the audio data, leading to a heap buffer overflow.
Users are advised to update to the patched version of MediaInfoLib, which is available on the project's GitHub page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.