Denial of Service Vulnerability in Nicotine+ by Nicotine+ Team
CVE-2021-45848

7.5HIGH

Key Information:

Vendor
CVE Published:
15 March 2022

What is CVE-2021-45848?

A Denial of Service (DoS) vulnerability exists in Nicotine+ versions 3.0.3 and later. This flaw allows an attacker using a modified Soulseek client to exploit the application by sending a file download request that includes a path with a null character. This request can cause Nicotine+ to crash, resulting in disruption of service for users. Mitigation strategies should be evaluated and implemented to protect against such vectors.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.