CVE-2017-11664

The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.
References
Link Resource
http://seclists.org/fulldisclosure/2017/Aug/12 Exploit Mailing List Third Party Advisory
https://www.exploit-db.com/exploits/42433/ Exploit Third Party Advisory VDB Entry
https://github.com/Mindwerks/wildmidi/commit/ad6d7cf88d6673167ca1f517248af9409a9f1be1 Patch Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:mindwerks:wildmidi:0.4.2:*:*:*:*:*:*:*

Information

Published : 2017-08-17 09:29

Updated : 2020-11-10 11:39


NVD link : CVE-2017-11664

Mitre link : CVE-2017-11664


JSON object : View

CWE
CWE-125

Out-of-bounds Read

Advertisement

dedicated server usa

Products Affected

mindwerks

  • wildmidi