fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Fluidsynth | Fluidsynth | * | 2.4.6 (including) |
| Fluidsynth | Ubuntu | plucky | * |
| Fluidsynth | Ubuntu | upstream | * |