PatchSiren cyber security CVE debrief
CVE-2017-5665 Libmp3splt Project CVE debrief
CVE-2017-5665 is a denial-of-service vulnerability in libmp3splt 0.9.2. According to NVD and the cited advisory, crafted input can reach splt_cue_export_to_file in cue.c and trigger a NULL pointer dereference, causing the application to crash. The issue is tracked as CWE-476 and was published on 2017-03-01; the NVD record was later modified on 2026-05-13.
- Vendor
- Libmp3splt Project
- Product
- Libmp3splt
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-01
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-01
- Advisory updated
- 2026-05-13
Who should care
Maintain ers and users of libmp3splt 0.9.2, especially distributions or applications that parse untrusted cue/audio files through libmp3splt.
Technical summary
NVD maps the issue to libmp3splt 0.9.2 and classifies it as CWE-476. The reported flaw is a NULL pointer dereference in splt_cue_export_to_file within cue.c, which can be triggered by crafted file input and results in a crash. NVD’s CVSS vector is AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, indicating availability impact with user interaction required.
Defensive priority
Medium. This is an availability-only crash issue, but it can still disrupt desktop or processing workflows that handle untrusted files. Prioritize if your environment processes user-supplied cue/audio content or ships libmp3splt in a user-facing application.
Recommended defensive actions
- Inventory systems and packages using libmp3splt 0.9.2.
- Apply vendor or distribution security updates for libmp3splt when available.
- Restrict or sandbox parsing of untrusted cue/audio files until patched.
- Treat unexpected crashes in file-processing workflows as potential indicators of this issue and review affected logs.
- If you maintain downstream software, verify whether your build inherits libmp3splt 0.9.2 and issue a patched release promptly.
Evidence notes
Supported by the NVD record and the cited Gentoo advisory reference. NVD lists the affected CPE as libmp3splt_project:libmp3splt:0.9.2 and assigns CVSS 3.0 AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H. The weakness is CWE-476. The public record was published on 2017-03-01 and modified on 2026-05-13.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5665 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5665
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5665 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5665
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://blogs.gentoo.org/ago/2017/01/29/mp3splt-null-pointer-dereference-in-splt_cue_export_to_file-cue-c/
[email protected] - Exploit, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.