Out-of-bounds write in libopenmpt - CVE-2018-11710
Published: August 7, 2018
libopenmpt
Detailed vulnerability description
The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code on the target system.
The vulnerability exists in soundlib/pattern.h due to an invalid write near address 0 in an out-of-memory situation. A remote attacker can supply a specially crafted AMS file with many nested pattern loops and cause the service to crash or execute arbitrary code with elevated privileges.