An integer overflow vulnerability in ptp-pack.c (ptp_unpack_OPL function) of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.
CVSS Details
- CVSS 3.0 Base Score: 6.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libmtp. | Sep 20, 2017 | Jun 23, 2017 |
| Debian | — | Upgrade libmtp | Feb 25, 2019 | Jun 23, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libmtp | Dec 4, 2019 | Jun 24, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libmtp | Dec 18, 2019 | Jun 24, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 16, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub