CVE-2018-14332

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
19/07/2018
Last modified:
21/07/2019

Description

An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clementine-player:clementine:1.3.1:*:*:*:*:*:*:*