[Bug 1143747] New: VUL-0: CVE-2019-14465: schismtracker: heap-based buffer overflow in fmt_mtm_load_song in fmt/mtm.c
http://bugzilla.opensuse.org/show_bug.cgi?id=1143747 Bug ID: 1143747 Summary: VUL-0: CVE-2019-14465: schismtracker: heap-based buffer overflow in fmt_mtm_load_song in fmt/mtm.c Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.0 Hardware: Other URL: https://smash.suse.de/issue/238554/ OS: Other Status: NEW Severity: Minor Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: atoptsoglou@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2019-14465 fmt_mtm_load_song in fmt/mtm.c in Schism Tracker 20190722 has a heap-based buffer overflow. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-14465 http://www.cvedetails.com/cve/CVE-2019-14465/ -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1143747 Alexandros Toptsoglou <atoptsoglou@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|security-team@suse.de |jengelh@inai.de -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1143747 http://bugzilla.opensuse.org/show_bug.cgi?id=1143747#c1 --- Comment #1 from Alexandros Toptsoglou <atoptsoglou@suse.com> --- Created attachment 812387 --> http://bugzilla.opensuse.org/attachment.cgi?id=812387&action=edit POC To run the reproducer simply run valgrind schismtracker test01.mtm OUTPUT ==4890== Process terminating with default action of signal 11 (SIGSEGV): dumping core ==4890== Bad permissions for mapped region at address 0xA052044 ==4890== at 0x4C355C5: __strcpy_chk (in /usr/lib64/valgrind/vgpreload_memcheck-amd64-linux.so) ==4890== by 0x142596: UnknownInlinedFun (string_fortified.h:90) ==4890== by 0x142596: fmt_mtm_load_song (mtm.c:139) ==4890== by 0x17B0F6: song_create_load (audio_loadsave.c:214) ==4890== by 0x17B23B: song_load_unchecked (audio_loadsave.c:270) ==4890== by 0x117876: main (main.c:1124) ==4890== -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com