UBUNTU-CVE-2018-14332
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-14332
Summary:
Details: An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.
References: https://ubuntu.com/security/CVE-2018-14332, https://github.com/clementine-player/Clementine/issues/6078, https://github.com/MostafaSoliman/Security-Advisories/blob/master/CVE-2018-14332, https://github.com/clementine-player/Clementine/blob/e5ab3e786f9adde12cec3cc90cfe8c1cc6b06320/src/moodbar/moodbarpipeline.cpp#L155, https://www.cve.org/CVERecord?id=CVE-2018-14332
Affected packages
Package
Name: clementine
Purl: pkg:deb/ubuntu/clementine?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
