adplug is vulnerable to arbitrary code execution. Multiple heap-based buffer overflow in CdtmLoader::load()
in dtm.cpp
allows an attacker to execute arbitrary code on the host OS.
github.com/adplug/adplug/commit/b48ac59168a478e673ebf6b1aad09b8b80027e2e
github.com/adplug/adplug/issues/86
github.com/adplug/adplug/issues/86
lists.fedoraproject.org/archives/list/[email protected]/message/Q32A64R2APAC5PXIMSYIEFDQX5AD4GAS/
lists.fedoraproject.org/archives/list/[email protected]/message/Q32A64R2APAC5PXIMSYIEFDQX5AD4GAS/
lists.fedoraproject.org/archives/list/[email protected]/message/U3PW6PLDTPSQQRHKTU2FB72SUB4Q66NE/
lists.fedoraproject.org/archives/list/[email protected]/message/U3PW6PLDTPSQQRHKTU2FB72SUB4Q66NE/