Medium severity5.0NVD Advisory· Published May 20, 2024· Updated Apr 15, 2026
CVE-2024-34952
CVE-2024-34952
Description
taurusxin ncmdump v1.3.2 was discovered to contain a segmentation violation via the NeteaseCrypt::FixMetadata() function at /src/ncmcrypt.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted .ncm file.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/Helson-S/FuzzyTesting/blob/master/ncmdump/dos_FixMetadata/dos_FixMetadata.assets/debug-coredump.pngnvd
- github.com/Helson-S/FuzzyTesting/blob/master/ncmdump/dos_FixMetadata/dos_FixMetadata.mdnvd
- github.com/Helson-S/FuzzyTesting/blob/master/ncmdump/dos_FixMetadata/poc/I1DWE0~Unvd
- github.com/Helson-S/FuzzyTesting/tree/master/ncmdump/dos_FixMetadatanvd
- github.com/Helson-S/FuzzyTesting/tree/master/ncmdump/dos_FixMetadata/pocnvd
- github.com/taurusxin/ncmdump/issues/18nvd
News mentions
0No linked articles in our index yet.