CVE-2022-48363

CVSS V2 None CVSS V3 None
Description
In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.
Overview
  • CVE ID
  • CVE-2022-48363
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-26T23:15:10
  • Last Modified Date
  • 2023-03-07T22:50:38
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:linuxfoundation:automotive_grade_linux:*:*:*:*:*:*:*:* 1 OR 0.23.8
History
Created Old Value New Value Data Type Notes
2023-04-17 05:28:20 Added to TrackCVE
2023-04-17 05:28:24 Weakness Enumeration new