Lucene search

K
freebsdFreeBSD329ECD60-AAF7-11EA-8659-10BF48E1088E
HistoryJun 08, 2020 - 12:00 a.m.

libadplug -- Various vulnerabilities

2020-06-0800:00:00
vuxml.freebsd.org
12

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.006

Percentile

79.2%

Malvineous on Github reports:

This release fixes the following security issues:

buffer overflow in .bmf
buffer overflow in .dtm
buffer overflow in .mkj
buffer overflow in .a2m
buffer overflow in .rad
buffer overflow in .mtk
double free and OOB reads in .u6m

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchlibadplug< 2.3.3UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.006

Percentile

79.2%