7.8
CVSSv3

CVE-2017-11311

Published: 17/07/2017 Updated: 27/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

soundlib/Load_psm.cpp in OpenMPT up to and including 1.26.12.00 and libopenmpt prior to 0.2.8461-beta26 has a heap buffer overflow with the potential for arbitrary code execution via a crafted PSM File that triggers use of the same sample slot for two samples.

Vulnerable Product Search on Vulmon Subscribe to Product

openmpt libopenmpt

openmpt openmpt

Vendor Advisories

Debian Bug report logs - #867579 libopenmpt: CVE-2017-11311 Package: src:libopenmpt; Maintainer for src:libopenmpt is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Jörn Heusipp <osmanx@problemloesungsmaschinede> Date: Fri, 7 Jul 2017 14:45:01 UTC Severity: grave Tags: fixed-upstr ...