alac
alac copied to clipboard
Severe Remote Code Execution vulnerability (from upstream)
Several vulnerabilities exist on the decoder, see macosforge/alac#22
Submitted a limited incomplete patch https://github.com/macosforge/alac/issues/22#issuecomment-1108128560 which doesn't fix the issue completely, fuzzing still discovered other deeper issues in how decoding is handled.
Many thanks for this.