PatchSiren

Libmp3splt Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Libmp3splt Project CVE published 2017-03-01

CVE-2017-5665

CVE-2017-5665 is a denial-of-service vulnerability in libmp3splt 0.9.2. According to NVD and the cited advisory, crafted input can reach splt_cue_export_to_file in cue.c and trigger a NULL pointer dereference, causing the application to crash. The issue is tracked as CWE-476 and was published on 2017-03-01; the NVD record was later modified on 2026-05-13.