Record summary

CVE-2017-11552 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.

Description

mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (memory corruption seen in a crash in the mad_decoder_run function in decoder.c in libmad) via a crafted MP3 file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBlibmad 0.15.1b - 'mp3' Memory CorruptionExploitDB exploitby qflb.wuNot analyzed1 file
ExploitDB

PoC details

References

4