NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a (newer commit after version 28.2) allows remote attackers to cause a Denial of Service.
References
Configurations
History
03 Feb 2026, 21:08
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/archersec/security-advisories/blob/master/owntone-server/owntone-server-advisory-2025.md - Patch, Vendor Advisory | |
| References | () https://github.com/owntone/owntone-server/commit/d857116e4143a500d6a1ea13f4baa057ba3b0028 - Patch | |
| CPE | cpe:2.3:a:owntone_project:owntone:*:*:*:*:*:*:*:* | |
| First Time |
Owntone Project owntone
Owntone Project |
Information
Published : 2026-01-20 21:16
Updated : 2026-02-03 21:08
NVD link : CVE-2025-57155
Mitre link : CVE-2025-57155
CVE.ORG link : CVE-2025-57155
JSON object : View
Products Affected
owntone_project
- owntone
CWE
CWE-476
NULL Pointer Dereference
