High severity7.5NVD Advisory· Published Mar 15, 2022· Updated Jun 17, 2026
CVE-2021-45848
CVE-2021-45848
Description
Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nicotine-plusPyPI | >= 3.0.3, < 3.2.1 | 3.2.1 |
Affected products
4- Nicotine+/Nicotine+description
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- github.com/nicotine-plus/nicotine-plus/issues/1777nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-p4v2-r99v-wjc2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-45848ghsaADVISORY
- security.gentoo.org/glsa/202210-20nvdThird Party AdvisoryWEB
- github.com/nicotine-plus/nicotine-plus/commit/0e3e2fac27a518f0a84330f1ddf1193424522045ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/HWYV53KERFH2EC4XI2IVVQFTV75E5XM6ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HWYV53KERFH2EC4XI2IVVQFTV75E5XM6/nvd
News mentions
0No linked articles in our index yet.