Beveiligingsadvies

CVE-2025-63648

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-01-20 00:00:00
Laatst bijgewerkt 2026-01-21 14:47:18
Toegewezen door mitre
CVSS-score 7.5
Status PUBLISHED

Beschrijving

A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackers to cause a Denial of Service (DoS) via sending a crafted DACP request to the server.