Popis
Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF bytes in URI fields by supplying a malicious XSPF playlist with XML numeric character references. Attackers can inject forged key-value lines through the location field into MPD protocol responses including playlistinfo, currentsong, and listplaylist outputs, as well as the state file writer, by exploiting Expat-s decoding of numeric character references prior to the character data callback.
CVSS 5.3EPSS 0.26%Riziko 0.54
Zobraziť zdroj- Zverejnené
- 2026-05-28 20:16:26
- Dotknuté verzie
- <0.24.11
- Typ
- Package
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N