rplay Denial-of-Service Vulnerability in librplay Library

Vulnerability

A denial-of-service vulnerability has been identified in rplay versions through 3.3.2. This issue, which causes a segmentation fault and crashes the audio daemon, arises in the 'memcpy' function within the 'RPLAY_DATA' case of 'rplay_unpack' in the 'librplay' library. The vulnerability can be exploited by sending crafted packet data to the rplay server, which processes the data without any authentication.

Impact

Exploitation of this vulnerability leads to a crash of the rplay audio daemon, causing a denial-of-service condition. Additionally, according to Vincent Lefèvre, this could disrupt the FVWM window manager by causing a crash, unless the manager has specific protections for modules.

Reproduction

The vulnerability can be reproduced by sending a packet with unsanitized data to an rplay server. This can be done using a simple harness that targets the 'rplay_unpack' function in the 'librplay' library, specifically the 'RPLAY_DATA' case. The rplay server processes the packet data without authentication, leading to a segmentation fault and a crash of the audio daemon.

Added: Oct 19, 2025, 1:16 AM
Updated: Oct 19, 2025, 2:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.4
remediation
0.0
relevance
0.8
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.