Related Vulnerabilities: CVE-2021-40826  

Clementine Music Player through 1.3.1 is vulnerable to a user mode write Access violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit this issue to cause a crash (DoS) of the clementine process or achieve arbitrary code execution in the context of the current user.

Severity Medium

Remote Yes

Type Arbitrary code execution

Description

Clementine Music Player through 1.3.1 is vulnerable to a user mode write Access violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit this issue to cause a crash (DoS) of the clementine process or achieve arbitrary code execution in the context of the current user.

AVG-2645 clementine 1.4.0rc1+759+gd033b38c4-1 Medium Vulnerable

https://voidsec.com/advisories/cve-2021-40826/