soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS file because of an invalid write near address 0 in an out-of-memory situation.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libopenmpt | Jul 30, 2024 | Jun 4, 2018 |
| Suse | — | Upgrade libmodplug1Upgrade libmodplug1-32bitUpgrade libopenmpt_modplug1-32bitUpgrade libmodplug-develUpgrade libopenmpt_modplug1Upgrade libopenmpt0-32bitUpgrade openmpt123Upgrade libopenmpt-develUpgrade libopenmpt0 | Jul 20, 2018 | Jun 4, 2018 |
| Ubuntu | — | Upgrade libopenmpt0 (Ubuntu Pro)Upgrade openmpt123 (Ubuntu Pro) | Mar 22, 2023 | Jun 4, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub