BackBox.org News
  • BackBox.org
  • Linux
  • Community
  • News
  • Services
  • Sitemap
  • Contact
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
Miniaudio and Adobe Acrobat Reader vulnerabilities

Miniaudio and Adobe Acrobat Reader vulnerabilities

March 13, 2025/in Company Blogs

Miniaudio and Adobe Acrobat Reader vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed a Miniaudio and three Adobe vulnerabilities.  

The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.    

For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.     

Miniaudio out-of-bounds write vulnerability 

Discovered by Emmanuel Tacheau of Cisco Talos.   

TALOS-2024-2063 (CVE-2024-41147) is an out-of-bounds write vulnerability in Miniaudio, a lightweight, single-file audio playback and capture library written in C. A missing allocation size check can cause a buffer overflow, leading to this out-of-bounds write. This vulnerability can be triggered by a specially crafted FLAC file, resulting in a memory corruption when in playback mode. The application sends raw audio data to Miniaudio, which is then played back through the default playback device as defined by the operating system. 

Adobe Acrobat out-of-bounds write vulnerability 

Discovered by KPC of Cisco Talos.   

TALOS-2025-2134 (CVE-2025-27163) and TALOS-2025-2136 (CVE-2025-27164) are out-of-bounds read vulnerabilities in the font functionality, which can lead to disclosure of sensitive information. TALOS-2025-2135 (CVE-2025-27158) is a memory corruption vulnerability, stemming from an uninitialized pointer in the font functionality of Adobe Acrobat, which can potentially lead to arbitrary code execution. A specially crafted font file embedded into a PDF can trigger these vulnerabilities. An attacker needs to trick the user into opening a malicious file. 

Cisco Talos Blog – ​Read More

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on LinkedIn
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png 0 0 admin https://www.backbox.org/wp-content/uploads/2018/09/website_backbox_text_black.png admin2025-03-13 19:06:432025-03-13 19:06:43Miniaudio and Adobe Acrobat Reader vulnerabilities
Search Search
Copyright © BackBox.org
  • Link to X
  • Link to Facebook
  • Link to LinkedIn
  • Link to Youtube
  • Link to Telegram
Link to: Patch it up: Old vulnerabilities are everyone’s problems Link to: Patch it up: Old vulnerabilities are everyone’s problems Patch it up: Old vulnerabilities are everyone’s problemsPatch it up: Old vulnerabilities are everyone’s problems Link to: Amazon is still hosting stalkerware victims’ data weeks after breach alert Link to: Amazon is still hosting stalkerware victims’ data weeks after breach alert Amazon is still hosting stalkerware victims’ data weeks after breach aler...
Scroll to top Scroll to top Scroll to top