The insert_note_steps function in readmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mid file. NOTE: a crash might be relevant when using the --background option.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade timidity | Jul 30, 2024 | Jul 31, 2017 |
| Freebsd | — | Upgrade timidity++-tcltkUpgrade timidity++-motifUpgrade timidity++-gtkUpgrade timidity++Upgrade timidity++-emacsUpgrade timidity++-slangUpgrade timidity++-xskinUpgrade timidity++-xaw | Dec 10, 2025 | Mar 2, 2020 |
| Suse | — | Upgrade timidity-debuginfoUpgrade timidity-debugsourceUpgrade timidity | Feb 27, 2018 | Jul 31, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 31, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub