CVE-2018-14332
low-risk
Published 2018-07-19
An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.
Do I need to act?
-
0.16% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10
Medium
LOCAL
/ LOW complexity
Affected Products (1)
Clementine
Affected Vendors
References (10)
Third Party Advisory
https://github.com/MostafaSoliman/Security-Advisories/blob/master/CVE-2018-14332
Third Party Advisory
https://github.com/clementine-player/Clementine/blob/e5ab3e786f9adde12cec3cc90cf...
Third Party Advisory
https://github.com/MostafaSoliman/Security-Advisories/blob/master/CVE-2018-14332
Third Party Advisory
https://github.com/clementine-player/Clementine/blob/e5ab3e786f9adde12cec3cc90cf...
24
/ 100
low-risk
Severity
18/34 · Moderate
Exploitability
1/34 · Minimal
Exposure
5/34 · Minimal