CVE-2017-14181: Aacplusenc Project Aacplusenc

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

DeleteBitBuffer in libbitbuf/bitbuffer.c in mp4tools aacplusenc 0.17.5 allows remote attackers to cause a denial of service (invalid memory write, SEGV on unknown address 0x000000000030, and application crash) or possibly have unspecified other impact via a crafted .wav file, aka a NULL pointer dereference.

Affected products

Published 2017-09-07. Last modified 2026-06-17.