An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://www.clementine-player.org/ | product |
https://github.com/clementine-player/Clementine | product |
https://github.com/riftsandroses/CVE-2024-50986/ | third party advisory exploit |