An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.
CVSS Details
- CVSS 3.0 Base Score: 6.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | alpine-linux-upgrade-libmtp | Sep 20, 2017 | Jun 23, 2017 |
| Debian | debian-upgrade-libmtp | Feb 25, 2019 | Jun 23, 2017 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-libmtp | Dec 4, 2019 | Jun 24, 2017 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-libmtp | Dec 18, 2019 | Jun 24, 2017 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Mar 16, 2017 | |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Jun 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub