CVE-2025-57156
EUVD-2026-333720.01.2026, 21:16
NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash).Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| owntone | owntone_server | 𝑥 ≤ 28.12 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration