VDB
CVE-2018-14332
CVE-2018-14332
PUBLISHED
An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.
EPSS 0.16% · 36.5th percentile
Risk Scores
EPSS Score
0.16%
36.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | clementine | 0, 1.3.1+git276-g3485bbe43+dfsg-1.1build1, 1.3.1+git276-g3485bbe43+dfsg-1.1 |
| Ubuntu:16.04:LTS | clementine | 0, 1.2.3+git1354-gdaddbde+dfsg-1build1, 1.2.3+git1354-gdaddbde+dfsg-1 |
| Ubuntu:24.04:LTS | clementine | *, 0, 1.4.0~rc1+git867-g9ef681b0e+dfsg-1ubuntu3 |
| Ubuntu:20.04:LTS | clementine | 1.3.1+git609-g623a53681+dfsg-1build1, 1.4.0~rc1+dfsg-1, 0 |
| Ubuntu:25.10 | clementine | 1.4.1+git27-g658f34ec4+dfsg-3ubuntu2, 1.4.1+git27-g658f34ec4+dfsg-3ubuntu1, 0 |
| Ubuntu:22.04:LTS | clementine | 1.4.0~rc1+git347-gfc4cb6fc7+dfsg-1build1, 1.4.0~rc1+git347-gfc4cb6fc7+dfsg-2, 0 |
Exploit Intelligence
- https://github.com/clementine-player/Clementine/issues/6078 (nist-nvd)
- https://github.com/clementine-player/Clementine/blob/e5ab3e786f9adde12cec3cc90cfe8c1cc6b06320/src/moodbar/moodbarpipeline.cpp#L155 (circl)
- https://github.com/MostafaSoliman/Security-Advisories/blob/master/CVE-2018-14332 (circl)
- openSUSE-SU-2019:1780 (circl)
- openSUSE-SU-2019:1959 (circl)
Timeline
- Jul 19, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-14332 third-party-advisory
- https://github.com/clementine-player/Clementine/issues/6078 third-party-advisory
- https://github.com/MostafaSoliman/Security-Advisories/blob/master/CVE-2018-14332 third-party-advisory
- https://github.com/clementine-player/Clementine/blob/e5ab3e786f9adde12cec3cc90cfe8c1cc6b06320/src/moodbar/moodbarpipeline.cpp#L155 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-14332 third-party-advisory