CVE-2017-15185: LIBMP3SPLT Project LIBMP3SPLT

Medium severity, CVSS 5.0. EPSS: 1.7% chance of exploitation in the next 30 days.

plugins/ogg.c in Libmp3splt 0.9.2 calls the libvorbis vorbis_block_clear function with uninitialized data upon detection of invalid input, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

Affected products

Published 2017-10-09. Last modified 2026-06-17.