Vulnerability Name:

CVE-2018-10017 (CCN-141589)

Assigned:2018-04-08
Published:2018-04-08
Updated:2020-10-15
Summary:soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial of service (out-of-bounds read) via an IT or MO3 file with many nested pattern loops.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-10017

Source: XF
Type: UNKNOWN
openmpt-cve201810017-dos(141589)

Source: CONFIRM
Type: Patch, Vendor Advisory
https://github.com/OpenMPT/openmpt/commit/7ebf02af2e90f03e0dbd0e18b8b3164f372fb97c

Source: CCN
Type: OpenMPT Web site
libopenmpt security updates 0.3.8, 0.2-beta31, 0.2.7561-beta20.5-p8, libopenmpt-0.2.7386-beta20.3-p11

Source: CONFIRM
Type: Patch, Vendor Advisory
https://lib.openmpt.org/libopenmpt/2018/04/08/security-updates-0.3.8-0.2-beta31-0.2.7561-beta20.5-p8-0.2.7386-beta20.3-p11/

Source: CONFIRM
Type: Release Notes, Vendor Advisory
https://openmpt.org/openmpt-1-27-07-00-released

Vulnerable Configuration:Configuration 1:
  • cpe:/a:openmpt:libopenmpt:*:*:*:*:*:*:*:* (Version < 0.3.8)
  • OR cpe:/a:openmpt:openmpt:*:*:*:*:*:*:*:* (Version < 1.27.07.00)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201810017
    V
    CVE-2018-10017
    2023-06-22
    oval:org.opensuse.security:def:7947
    P
    libmodplug-devel-0.3.28-2.13.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:784
    P
    Security update for dpdk (Important)
    2022-09-27
    oval:org.opensuse.security:def:3326
    P
    perl-DBD-mysql-4.021-12.5.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94956
    P
    libmodplug-devel-0.3.28-2.13.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1238
    P
    Security update for the Linux Kernel (Important)
    2022-06-14
    oval:org.opensuse.security:def:1594
    P
    Security update for the Linux Kernel (Important)
    2022-03-30
    oval:org.opensuse.security:def:94065
    P
    (Moderate)
    2022-03-24
    oval:org.opensuse.security:def:112739
    P
    libopenmpt-devel-0.5.11-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:1710
    P
    Security update for tomcat (Moderate)
    2021-11-16
    oval:org.opensuse.security:def:106211
    P
    libopenmpt-devel-0.5.11-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71158
    P
    conntrack-tools-1.4.4-1.29 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71271
    P
    libjson-c-devel-0.13-1.19 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64571
    P
    Security update for apache2 (Important)
    2021-09-03
    oval:org.opensuse.security:def:1120
    P
    Security update for go1.15 (Moderate)
    2021-08-20
    oval:org.opensuse.security:def:47320
    P
    libXrandr2-1.5.0-6.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48220
    P
    libvpx1-1.3.0-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47306
    P
    libIlmImf-Imf_2_1-21-2.1.0-4.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48006
    P
    file-5.22-10.12.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47858
    P
    powerpc-utils-1.3.5-3.8 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47766
    P
    libpng16-16-1.6.8-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47305
    P
    libHX28-3.18-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47634
    P
    gstreamer-plugins-base-1.8.3-12.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47441
    P
    logwatch-7.4.3-15.65 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48304
    P
    screen-4.0.4-23.3.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:101205
    P
    libmodplug-devel-0.3.19-2.10.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72518
    P
    libmodplug-devel-0.3.19-2.10.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1952
    P
    python3-tools-3.6.13-3.78.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1950
    P
    perl-solv-0.7.19-3.20.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1930
    P
    kernel-docs-5.3.18-57.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1941
    P
    pam-devel-32bit-1.3.0-6.29.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1936
    P
    nasm-2.14.02-3.4.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100778
    P
    amavisd-new-2.11.1-6.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1932
    P
    libpcp-devel-4.3.1-3.11.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62799
    P
    libmodplug-devel-0.3.19-2.10.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1958
    P
    xstream-1.4.15-3.5.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1476
    P
    Security update for php7 (Important)
    2021-08-06
    oval:org.opensuse.security:def:48787
    P
    libfbembed2_5-2.5.2.26539-13.42 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48589
    P
    pam-modules-12.1-23.6 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48464
    P
    libXcursor1-1.1.14-3.59 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48431
    P
    gnome-settings-daemon-3.20.1-40.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48448
    P
    jakarta-commons-fileupload-1.1.1-120.113 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48533
    P
    libpcsclite1-1.8.10-3.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48366
    P
    apache-commons-daemon-1.0.15-4.181 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:1975
    P
    ntp-4.2.8p11-2.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48928
    P
    libiso9660-8-0.90-6.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48447
    P
    iputils-s20121221-2.17 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48462
    P
    libX11-6-1.6.2-4.10 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:1987
    P
    openldap2-2.4.46-9.3.1 on GA media (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:1985
    P
    libopenssl-1_0_0-devel-1.0.2p-3.14.2 on GA media (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:64484
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:1980
    P
    gv-3.7.4-1.41 on GA media (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:66745
    P
    Security update for ImageMagick (Moderate)
    2021-04-20
    oval:org.opensuse.security:def:67818
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 15) (Important)
    2021-03-17
    oval:org.opensuse.security:def:69996
    P
    Security update for kernel-firmware (Important)
    2021-03-03
    oval:org.opensuse.security:def:103570
    P
    libmodplug-devel-0.3.9-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89915
    P
    libmodplug-devel-0.3.9-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62565
    P
    libmodplug-devel-0.3.9-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107444
    P
    libmodplug-devel-0.3.19-2.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72284
    P
    libmodplug-devel-0.3.9-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62683
    P
    libmodplug-devel-0.3.19-2.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49022
    P
    libntfs-3g84-2013.1.13-5.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72402
    P
    libmodplug-devel-0.3.19-2.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117002
    P
    libmodplug-devel-0.3.19-2.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2635
    P
    Security update for libopenmpt (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2625
    P
    Security update for runc (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:49625
    P
    fwupd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49732
    P
    crash on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49563
    P
    libmpg123-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51070
    P
    Security update for libopenmpt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49659
    P
    libcdio++0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49496
    P
    ImageMagick on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70101
    P
    libmodplug-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51008
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:49407
    P
    gnome-keyring on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49176
    P
    libipa_hbac-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49561
    P
    libmodplug-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73318
    P
    socat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49628
    P
    gdk-pixbuf-query-loaders-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49507
    P
    cups-pk-helper on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49679
    P
    libmodplug-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66653
    P
    xen-libs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67918
    P
    libmodplug-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73436
    P
    libmodplug-devel on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.artful:def:201810017000
    V
    CVE-2018-10017 on Ubuntu 17.10 (artful) - low.
    2018-04-11
    oval:com.ubuntu.cosmic:def:2018100170000000
    V
    CVE-2018-10017 on Ubuntu 18.10 (cosmic) - low.
    2018-04-11
    oval:com.ubuntu.bionic:def:201810017000
    V
    CVE-2018-10017 on Ubuntu 18.04 LTS (bionic) - low.
    2018-04-11
    oval:com.ubuntu.bionic:def:2018100170000000
    V
    CVE-2018-10017 on Ubuntu 18.04 LTS (bionic) - low.
    2018-04-11
    oval:com.ubuntu.cosmic:def:201810017000
    V
    CVE-2018-10017 on Ubuntu 18.10 (cosmic) - low.
    2018-04-11
    oval:com.ubuntu.disco:def:2018100170000000
    V
    CVE-2018-10017 on Ubuntu 19.04 (disco) - low.
    2018-04-11
    BACK
    openmpt libopenmpt *
    openmpt openmpt *