PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5666 Mp3splt Project CVE debrief

CVE-2017-5666 is an invalid-free flaw in free_options() in options_manager.c in mp3splt 2.6.2. When a crafted file is processed, the application can crash, resulting in denial of service. The official NVD record classifies the issue as CWE-416 with CVSS 3.0 5.5/Medium (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).

Vendor
Mp3splt Project
Product
Mp3splt
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-01
Original CVE updated
2026-05-13
Advisory published
2017-03-01
Advisory updated
2026-05-13

Who should care

Anyone running or packaging mp3splt 2.6.2, especially systems that process user-supplied or otherwise untrusted files. Availability-sensitive environments should treat this as a crash-risk issue.

Technical summary

The vulnerable code path is in free_options() within options_manager.c. NVD maps the weakness to CWE-416 (Use After Free / invalid free class) and notes a user-interaction requirement in its CVSS vector. The supplied CVE description says a crafted file can trigger the crash; the resulting impact in the official record is denial of service, with no confidentiality or integrity impact assigned.

Defensive priority

Medium priority: the issue is limited to a specific version and is primarily a denial-of-service condition, but it can reliably crash processing of crafted input and should be addressed in any workflow that ingests untrusted files.

Recommended defensive actions

  • Inventory any systems, packages, or containers that include mp3splt 2.6.2.
  • Avoid processing untrusted or externally supplied files with mp3splt until a verified non-vulnerable build is in place.
  • If removal is not immediately possible, isolate the tool in a sandbox or low-privilege environment to reduce blast radius from crashes.
  • Monitor jobs and services that invoke mp3splt for unexpected termination or repeated crash loops.
  • Track vendor or distribution advisories for a patched release before re-enabling normal file-processing workflows.

Evidence notes

The supplied official record identifies the weakness as CWE-416 and provides a CVSS vector of AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H. The CVE description states that a crafted file can trigger an invalid free and crash. The reference set also includes a Gentoo blog advisory tagged as Exploit/Third Party Advisory and a SecurityFocus BID reference. This debrief does not rely on any exploit details beyond the official descriptions and references.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5666 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5666

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5666 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5666

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.