PT-2020-19597 · Music Player Daemon · Mpd

Dadv

·

Published

2020-10-06

·

Updated

2023-07-19

·

CVE-2020-7465

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MPD versions prior to 5.9
Description The issue allows a remote attacker who can send specifically crafted L2TP control packets with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service due to memory corruption.
Recommendations For versions prior to 5.9, update to version 5.9 or later to resolve the issue.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2020-7465

Affected Products

Mpd