7.5
CVE-2022-48363
- EPSS 1.17%
- Veröffentlicht 26.02.2023 23:15:10
- Zuletzt bearbeitet 13.05.2026 20:00:18
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Musicpd ≫ Music Player Daemon Version < 0.23.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.17% | 0.632 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28484
https://gerrit.automotivelinux.org/gerrit/c/src/libqtappfw/+/28485
https://gerrit.automotivelinux.org/gerrit/q/project:src%252Flibqtappfw+status:open
https://jira.automotivelinux.org/browse/SPEC-4661