An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.
{
"cpe": "cpe:2.3:a:clementine-player:clementine:1.3.1:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.3.1"
},
{
"last_affected": "1.3.1"
}
],
"source": "CPE_STRING"
}