Impact
The DSF parser in music‑metadata incorrectly handles unrecognized chunks by calling tokenizer.ignore without awaiting the returned promise and without rejecting chunks smaller than the 12‑byte header. A crafted DSF file can trigger a negative ignore length, producing a RangeError that, because of the detachment from the parseBuffer promise in strtok3 10.3.5 or later, becomes an unhandled rejection under Node.js default behavior. The parse call may appear to resolve before the crash, bypassing the per‑parse try/catch wrapper; the effect is a process termination that removes the service from availability. Confidentiality and integrity remain unaffected.
Affected Systems
The vulnerability affects the Borewit music‑metadata library prior to version 11.15.0. Any Node.js application that parses DSF files using an older release of this library is potentially impacted.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity; EPSS data is not available and the issue is not listed in CISA KEV. The attack vector is inferred to be the delivery of a malicious DSF file to any code path that invokes the music‑metadata parser. No special privileges or additional components are required. An attacker can repeatedly supply crafted DSF files to repeatedly crash or starve a long‑running service, constituting a denial‑of‑service attack.
OpenCVE Enrichment
Github GHSA