PT-2020-19598 · Music Player Daemon · Mpd

Dadv

·

Published

2020-10-06

·

Updated

2023-07-19

·

CVE-2020-7466

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MPD versions prior to 5.9
Description The issue allows a remote attacker who can send specifically crafted PPP authentication messages to cause the daemon to read beyond an allocated memory buffer, resulting in a denial of service condition.
Recommendations For versions prior to 5.9, update to version 5.9 or later to resolve the issue.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2020-7466

Affected Products

Mpd