CVE-2021-21417

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
29/04/2021
Last modified:
14/09/2021

Description

fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fluidsynth:fluidsynth:*:*:*:*:*:*:*:* 2.1.8 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*