CVE Vulnerabilities

CVE-2021-40826

NULL Pointer Dereference

Published: Dec 15, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit this issue to cause a crash (DoS) of the clementine.exe process or achieve arbitrary code execution in the context of the current logged-in Windows user.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
ClementineClementine-player*1.3.1 (including)
ClementineUbuntubionic*
ClementineUbuntufocal*
ClementineUbuntuhirsute*
ClementineUbuntuimpish*
ClementineUbuntukinetic*
ClementineUbuntulunar*
ClementineUbuntumantic*
ClementineUbuntuoracular*
ClementineUbuntuplucky*
ClementineUbuntutrusty*
ClementineUbuntuxenial*

Potential Mitigations

References