An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Clementine | Clementine-player | 1.3.1 (including) | 1.3.1 (including) |
Clementine | Ubuntu | artful | * |
Clementine | Ubuntu | bionic | * |
Clementine | Ubuntu | cosmic | * |
Clementine | Ubuntu | disco | * |
Clementine | Ubuntu | eoan | * |
Clementine | Ubuntu | groovy | * |
Clementine | Ubuntu | hirsute | * |
Clementine | Ubuntu | impish | * |
Clementine | Ubuntu | kinetic | * |
Clementine | Ubuntu | lunar | * |
Clementine | Ubuntu | mantic | * |
Clementine | Ubuntu | trusty | * |
Clementine | Ubuntu | xenial | * |