PT-2019-4197 · Openmpt+2 · Libopenmpt+2

Antonio Morales Maldonado

·

Published

2019-10-03

·

Updated

2026-04-23

·

CVE-2019-17113

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libopenmpt versions prior to 0.3.19 libopenmpt versions 0.4.x prior to 0.4.9
Description The issue is related to the functions ModPlug InstrumentName and ModPlug SampleName in libopenmpt modplug.c, which do not properly restrict the lengths of output-buffer strings. This can lead to a buffer overflow, allowing a remote attacker to access confidential data, compromise data integrity, and cause a denial of service.
Recommendations For libopenmpt versions prior to 0.3.19, update to version 0.3.19 or later. For libopenmpt versions 0.4.x prior to 0.4.9, update to version 0.4.9 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04793
CVE-2019-17113
DLA-2308-1
DSA-4729-1
OPENSUSE-SU-2019:2306-1
OPENSUSE-SU-2019:2319-1
OPENSUSE-SU-2019_2306-1
OPENSUSE-SU-2019_2319-1
OPENSUSE-SU-2024:10965-1
SUSE-SU-2019:2622-1
SUSE-SU-2019_2622-1
USN-8206-1

Affected Products

Suse
Ubuntu
Libopenmpt