No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Musicplayerdaemon
Musicplayerdaemon mpd |
|
| Vendors & Products |
Musicplayerdaemon
Musicplayerdaemon mpd |
Thu, 28 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 28 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD commands referencing a malicious HTTP audio source to cause the unpack loop to write 1366 entries into a 1365-entry buffer, overwriting four bytes past the array boundary with three attacker-controlled bytes from an HTTP response body, resulting in daemon termination or potential code execution. | |
| Title | Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be | |
| Weaknesses | CWE-193 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-29T19:14:38.903Z
Reserved: 2026-05-27T17:40:12.738Z
Link: CVE-2026-49127
Updated: 2026-05-29T19:14:34.886Z
Status : Deferred
Published: 2026-05-28T20:16:26.387
Modified: 2026-05-29T14:07:47.980
Link: CVE-2026-49127
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:48:01Z