Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
libmodplug <= 0.8.9.1 - Out-of-Bounds Read in pat_smplooped via Crafted MIDI File
Vulnerability Description
libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array. The index is the smpno field of a parsed MIDI event, which is initialised to zero and only later overwritten from a program-change parameter, so an event reaching the note test before an instrument is assigned carries zero. A 32-byte MIDI file supplied to the library's public ModPlug_Load entry point drives the path through CSoundFile::Create, CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read out of bounds determines whether a note event is treated as looping, so adjacent static storage influences playback state.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
跨界内存读
Vulnerability Title
konstanty bialkowski libmodplug 缓冲区错误漏洞
Vulnerability Description
konstanty bialkowski libmodplug是konstanty bialkowski个人开发者开源的一个音频模块播放库。 konstanty bialkowski libmodplug 0.8.9.1及之前版本存在缓冲区错误漏洞,该漏洞源于src/load_pat.cpp中的pat_smplooped函数仅验证样本索引上限后减一,导致索引为零时读取静态数组前一个字节,可能影响播放状态。
CVSS Information
N/A
Vulnerability Type
N/A