In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libopenmpt | Jul 21, 2020 | Oct 4, 2019 |
| Suse | — | Upgrade libmodplug-develUpgrade libmodplug1-32bitUpgrade libmodplug1Upgrade libopenmpt_modplug1-32bitUpgrade libopenmpt_modplug1Upgrade libopenmpt0-32bitUpgrade libopenmpt0Upgrade libopenmpt-develUpgrade openmpt123 | Oct 12, 2019 | Oct 4, 2019 |
| Ubuntu | — | Upgrade libopenmpt-dev (Ubuntu Pro)Upgrade libopenmpt0 (Ubuntu Pro)Upgrade openmpt123 (Ubuntu Pro)Upgrade libopenmpt-modplug1 (Ubuntu Pro) | Jun 26, 2025 | Oct 4, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub