Junglewise Threat Intelligence

CVE-2024-21522: audify array index validation denial of service

CVE-2024-21522 · Severity: low · CVSS 3.1 · Published 2024-07-10

Vendors: npm.

Executive brief

audify is a Node.js library for encoding and decoding Opus audio format. A flaw in input validation allows attackers to pass negative values to the OpusDecoder functions, causing the process to crash and preventing legitimate audio decoding operations. This results in denial of service for any application relying on audify.

Technical details

The vulnerability is an improper validation of array index (CWE-129) in the OpusDecoder.decode() and OpusDecoder.decodeFloat() functions. When a negative frameSize parameter is passed to these methods, it is not validated, leading to an attempt to allocate an array with a negative length. This causes a C++ std::bad_array_new_length exception and process termination. The vulnerability affects all versions up to and including 1.9.0. No authentication or special privileges are required; any code calling these functions with untrusted input is exploitable. The attack vector is network-accessible if the decoding functions are exposed through an API endpoint.

Affected products

  • audify audify all versions up to 1.9.0

Timeline

  • 2024-01-15: disclosed: Vulnerability reported on GitHub gist
  • 2024-07-10: advisory: GHSA-7vhm-fmph-7wxw and CVE-2024-21522 published

References