CVE-2017-11548 describes a denial-of-service vulnerability in Xiph.Org libao 1.2.0, specifically within the _tokenize_matrix function in audio_out.c. A remote attacker can trigger memory corruption by providing a specially crafted MP3 file to a system using the affected libao version. This vulnerability is rated Medium severity (CVSS 5.5) with a local attack vector requiring user interaction, leading to a high impact on availability. There is no impact on confidentiality or integrity. While not listed on the CISA KEV catalog or actively exploited, an exploit (EDB-42400) is publicly available on ExploitDB. The CVE has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.0CPE matchmatch criteria | cpe:2.3:a:xiph:libao:1.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.