Withdrawn Advisory
This advisory was withdrawn on Apr 27, 2026. Withdrawn advisories are no longer considered active.
In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.
0.2.8760~beta27-10.3.1-10.3.2-10.3.3-10.3.4-10.3.6-10.3.6-1ubuntu0.1~esm1Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:HI:HA:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H