CVE-2018-7263

CRITICAL

Underbit Libmad < 0.15.1b - Double Free

Title source: rule

Description

The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file. NOTE: this may overlap CVE-2017-11552.

Scores

CVSS v3 9.8
EPSS 0.0083
EPSS Percentile 74.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status published

Affected Products (1)

underbit/libmad < 0.15.1b

Timeline

Published Feb 20, 2018
Tracked Since Feb 18, 2026