6.8
CVSSv2

CVE-2018-10777

Published: 07/05/2018 Updated: 12/06/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the WriteMP3GainAPETag function in apetag.c in mp3gain up to and including 1.5.2-r2 allows remote malicious users to cause a denial of service (application crash) or possibly have unspecified other impact.

Vulnerable Product Search on Vulmon Subscribe to Product

mp3gain mp3gain 1.5.2

mp3gain mp3gain

Vendor Advisories

Debian Bug report logs - #973932 mp3gain: CVE-2018-10777, CVE-2019-18359: Crashes with fuzzing PoC Package: mp3gain; Maintainer for mp3gain is Scott Hardin <scottnhardin@gmailcom>; Source for mp3gain is src:mp3gain (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Sat, 7 Nov 2020 19:30:02 UTC ...