soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial of service (out-of-bounds read) via an IT or MO3 file with many nested pattern loops.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libopenmpt | Jul 30, 2024 | Apr 11, 2018 |
| Suse | — | Upgrade libmodplug1Upgrade libopenmpt0Upgrade openmpt123Upgrade libmodplug-develUpgrade libmodplug1-32bitUpgrade libopenmpt-develUpgrade libopenmpt_modplug1Upgrade libopenmpt_modplug1-32bitUpgrade libopenmpt0-32bit | Jul 20, 2018 | Apr 11, 2018 |
| Ubuntu | — | Upgrade openmpt123 (Ubuntu Pro)Upgrade libopenmpt0 (Ubuntu Pro) | Mar 22, 2023 | Apr 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub