alac
                                
                                 alac copied to clipboard
                                
                                    alac copied to clipboard
                            
                            
                            
                        Severe Remote Code Execution vulnerability (from upstream)
Several vulnerabilities exist on the decoder, see macosforge/alac#22
Submitted a limited incomplete patch https://github.com/macosforge/alac/issues/22#issuecomment-1108128560 which doesn't fix the issue completely, fuzzing still discovered other deeper issues in how decoding is handled.
Many thanks for this.