Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-40827
HistoryDec 15, 2021 - 12:00 a.m.

CVE-2021-40827

2021-12-1500:00:00
ubuntu.com
ubuntu.com
7

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

39.3%

Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used) is
vulnerable to a Read Access Violation on Block Data Move, affecting the MP3
file parsing functionality at memcpy+0x265. The vulnerability is triggered
when the user opens a crafted MP3 file or loads a remote stream URL that is
mishandled by Clementine. Attackers could exploit this issue to cause a
crash (DoS) of the clementine.exe process or achieve arbitrary code
execution in the context of the current logged-in Windows user.

Notes

Author Note
ebarretto Might be Windows specific, needs checking

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

39.3%

Related for UB:CVE-2021-40827