openwrt ▾
›
master ▾
›
component
›
owntone
Component Overview
Vulnerability Overview
Name
owntone
Version
29.0-r1
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:owntone:owntone_server:29.0:*:*:*:*:*:*:*
Other Versions
#
Project
Branch
Version
openwrt
openwrt-25.12
29.0-r1
Vulnerabilities
#
Name
Analysis
Description
CVE-2025-63648
Exploitable
A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackers to cause a Denial of Service (DoS) via sending a crafted DACP request to the server.