PT-2019-4197 · Openmpt+2 · Libopenmpt+2
Antonio Morales Maldonado
·
Published
2019-10-03
·
Updated
2026-04-23
·
CVE-2019-17113
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libopenmpt versions prior to 0.3.19
libopenmpt versions 0.4.x prior to 0.4.9
Description
The issue is related to the functions
ModPlug InstrumentName and ModPlug SampleName in libopenmpt modplug.c, which do not properly restrict the lengths of output-buffer strings. This can lead to a buffer overflow, allowing a remote attacker to access confidential data, compromise data integrity, and cause a denial of service.Recommendations
For libopenmpt versions prior to 0.3.19, update to version 0.3.19 or later.
For libopenmpt versions 0.4.x prior to 0.4.9, update to version 0.4.9 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Ubuntu
Libopenmpt