CVE-2017-11552 describes a memory corruption vulnerability in mpg321 version 0.3.2-1, specifically within its interaction with libmad 0.15.1b, affecting the underbit mad_libmad product. This medium-severity vulnerability (CVSS 6.5) can be triggered remotely by an unauthenticated attacker via a crafted MP3 file, leading to a denial of service through a crash in the mad_decoder_run function. While there is an ExploitDB entry (EDB-42409) detailing memory corruption, there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.15.1bCPE matchmatch criteria | cpe:2.3:a:underbit:mad_libmad:0.15.1b:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.