owntone-server
cpe:2.3:a:owntone_project:owntone:*:*:*:*:*:*:*
- <= 28.2
A NULL pointer dereference vulnerability has been identified in the daap_reply_groups function of owntone-server, in versions prior to the commit d857116e4143a500d6a1ea13f4baa057ba3b0028. This vulnerability allows remote attackers to cause a denial-of-service condition by sending crafted DAAP requests that trigger the null pointer dereference, leading to a crash of the server.
Exploitation of this vulnerability causes a denial-of-service condition, crashing the server.
Users can upgrade to owntone-server version 29.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.