MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively long URL string. Attackers can create a malicious MP3 file with a buffer containing 4000 bytes of data appended to a URL, which causes the application to crash when the file is opened through the File > Open URL dialog.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Mar 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively long URL string. Attackers can create a malicious MP3 file with a buffer containing 4000 bytes of data appended to a URL, which causes the application to crash when the file is opened through the File > Open URL dialog. | |
| Title | MediaMonkey 4.1.23 Denial of Service via Malformed URL | |
| Weaknesses | CWE-226 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-21T12:47:10.769Z
Reserved: 2026-03-21T12:38:23.575Z
Link: CVE-2019-25571
No data.
Status : Received
Published: 2026-03-21T13:16:21.017
Modified: 2026-03-21T13:16:21.017
Link: CVE-2019-25571
No data.
OpenCVE Enrichment
No data.