CVE Vulnerabilities

CVE-2017-5665

NULL Pointer Dereference

Published: Mar 01, 2017 | Modified: Mar 03, 2017
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

The splt_cue_export_to_file function in cue.c in libmp3splt 0.9.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Libmp3splt Libmp3splt_project 0.9.2 (including) 0.9.2 (including)
Mp3splt Ubuntu artful *
Mp3splt Ubuntu bionic *
Mp3splt Ubuntu cosmic *
Mp3splt Ubuntu devel *
Mp3splt Ubuntu disco *
Mp3splt Ubuntu eoan *
Mp3splt Ubuntu esm-apps/bionic *
Mp3splt Ubuntu esm-apps/focal *
Mp3splt Ubuntu esm-apps/jammy *
Mp3splt Ubuntu esm-apps/noble *
Mp3splt Ubuntu esm-apps/xenial *
Mp3splt Ubuntu focal *
Mp3splt Ubuntu groovy *
Mp3splt Ubuntu hirsute *
Mp3splt Ubuntu impish *
Mp3splt Ubuntu jammy *
Mp3splt Ubuntu kinetic *
Mp3splt Ubuntu lunar *
Mp3splt Ubuntu mantic *
Mp3splt Ubuntu noble *
Mp3splt Ubuntu oracular *
Mp3splt Ubuntu precise *
Mp3splt Ubuntu trusty *
Mp3splt Ubuntu upstream *
Mp3splt Ubuntu xenial *
Mp3splt Ubuntu yakkety *
Mp3splt Ubuntu zesty *

Potential Mitigations

References