CVE-2019-17113
published 2019-10-04CVE-2019-17113: In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.70%
84.3th percentile
In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libopenmpt | < libopenmpt 0.4.9-1 (bookworm) | libopenmpt 0.4.9-1 (bookworm) |
| openmpt | libopenmpt | < 0.3.19 | 0.3.19 |
| openmpt | libopenmpt | >= 0 < 0.4.9-1 | 0.4.9-1 |
| openmpt | libopenmpt | >= 0 < 0.4.9-1 | 0.4.9-1 |
| openmpt | libopenmpt | >= 0 < 0.4.9-1 | 0.4.9-1 |
| openmpt | libopenmpt | >= 0 < 0.4.9-1 | 0.4.9-1 |
| openmpt | libopenmpt | >= 0.4.0 < 0.4.9 | 0.4.9 |
| ubuntu | libopenmpt | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenMPT vulnerability
vendor_ubuntu·2026-04-23
CVE-2019-17113 OpenMPT vulnerability
Title: OpenMPT vulnerability
Summary: OpenMPT could be made to crash if it received specially crafted input.
Antonio Morales Maldonado discovered that OpenMPT did not properly limit
the length of strings in certain cases, leading to a buffer overflow.
An attacker could possibly use this issue to cause OpenMPT to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-17113: libopenmpt - In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and M...
vendor_debian·2019·CVSS 9.8
CVE-2019-17113 [CRITICAL] CVE-2019-17113: libopenmpt - In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and M...
In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.
Scope: local
bookworm: resolved (fixed in 0.4.9-1)
bullseye: resolved (fixed in 0.4.9-1)
forky: resolved (fixed in 0.4.9-1)
sid: resolved (fixed in 0.4.9-1)
trixie: resolved (fixed in 0.4.9-1)
GHSA
GHSA-9qmp-r7mf-m39c: In libopenmpt before 0
ghsa_unreviewed·2022-05-24
CVE-2019-17113 [HIGH] GHSA-9qmp-r7mf-m39c: In libopenmpt before 0
In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.
OSV
CVE-2019-17113: In libopenmpt before 0
osv·2019-10-04·CVSS 9.8
CVE-2019-17113 [CRITICAL] CVE-2019-17113: In libopenmpt before 0
In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00044.htmlhttps://github.com/OpenMPT/openmpt/commit/927688ddab43c2b203569de79407a899e734fabehttps://github.com/OpenMPT/openmpt/compare/libopenmpt-0.3.18...libopenmpt-0.3.19https://github.com/OpenMPT/openmpt/compare/libopenmpt-0.4.8...libopenmpt-0.4.9https://lists.debian.org/debian-lts-announce/2020/08/msg00003.htmlhttps://source.openmpt.org/browse/openmpt/trunk/OpenMPT/?op=revision&rev=12127&peg=12127https://www.debian.org/security/2020/dsa-4729http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00044.htmlhttps://github.com/OpenMPT/openmpt/commit/927688ddab43c2b203569de79407a899e734fabehttps://github.com/OpenMPT/openmpt/compare/libopenmpt-0.3.18...libopenmpt-0.3.19https://github.com/OpenMPT/openmpt/compare/libopenmpt-0.4.8...libopenmpt-0.4.9https://lists.debian.org/debian-lts-announce/2020/08/msg00003.htmlhttps://source.openmpt.org/browse/openmpt/trunk/OpenMPT/?op=revision&rev=12127&peg=12127https://www.debian.org/security/2020/dsa-4729
2019-10-04
Published