CVE-2017-14410 describes a buffer over-read vulnerability in the III_i_stereo function within mpglibDBL, specifically affecting MP3Gain version 1.5.2. This flaw can lead to an application crash, resulting in a remote denial of service. The vulnerability is rated Medium severity (CVSS 5.5) with a low attack complexity, requiring user interaction (e.g., opening a malicious MP3 file) and local access to trigger. Its primary impact is denial of service, with no confidentiality or integrity impacts. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The CVE has received minimal community discussion and media coverage, indicating low public awareness and a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.2CPE matchmatch criteria | cpe:2.3:a:mp3gain:mp3gain:1.5.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.