NULL Pointer Dereference Vulnerability in Owntone Server by Owntone
CVE-2025-63647
7.5HIGH
What is CVE-2025-63647?
A vulnerability exists in the Owntone Server where a NULL pointer dereference within the parse_meta function can be exploited by attackers. By crafting specific DAAP (Digital Audio Access Protocol) requests, an attacker can trigger a Denial of Service (DoS), causing the server to become unresponsive. This issue highlights the need for proper input validation and error handling to maintain service availability.
