Vulnerabilities > CVE-2019-14497 - Out-of-bounds Write vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based buffer overflow.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 1 | |
OS | 2 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DLA-1961.NASL |
description | Fredric discovered a couple of buffer overflows in MilkyTracker, of which, a brief description is given below. CVE-2019-14464 XMFile::read in XMFile.cpp in milkyplay in MilkyTracker had a heap-based buffer overflow. CVE-2019-14496 LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker had a stack-based buffer overflow. CVE-2019-14497 ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker had a heap-based buffer overflow. For Debian 8 |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 130130 |
published | 2019-10-22 |
reporter | This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/130130 |
title | Debian DLA-1961-1 : milkytracker security update |
References
- https://github.com/milkytracker/MilkyTracker/issues/182
- https://github.com/milkytracker/MilkyTracker/issues/182
- https://lists.debian.org/debian-lts-announce/2019/10/msg00029.html
- https://lists.debian.org/debian-lts-announce/2019/10/msg00029.html
- https://lists.debian.org/debian-lts-announce/2020/07/msg00023.html
- https://lists.debian.org/debian-lts-announce/2020/07/msg00023.html
- https://usn.ubuntu.com/4499-1/
- https://usn.ubuntu.com/4499-1/