CVE-2017-5665

Name
CVE-2017-5665
Description
The splt_cue_export_to_file function in cue.c in libmp3splt 0.9.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org http://www.securityfocus.com/bid/95906
Exploit https://blogs.gentoo.org/ago/2017/01/29/mp3splt-null-pointer-dereference-in-splt_cue_export_to_file-cue-c/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libmp3splt_project:libmp3splt:0.9.2:*:*:*:*:*:*:* libmp3splt == None == 0.9.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libmp3splt edge-community 0.9.2-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libmp3splt edge-community 0.9.2-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libmp3splt 3.23-community 0.9.2-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable