CVE-2017-11664

The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.
References
Link Resource
http://seclists.org/fulldisclosure/2017/Aug/12 Exploit Mailing List Third Party Advisory
https://github.com/Mindwerks/wildmidi/commit/ad6d7cf88d6673167ca1f517248af9409a9f1be1 Patch Third Party Advisory
https://www.exploit-db.com/exploits/42433/ Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:mindwerks:wildmidi:0.4.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-08-17 16:29

Updated : 2024-02-04 19:29


NVD link : CVE-2017-11664

Mitre link : CVE-2017-11664

CVE.ORG link : CVE-2017-11664


JSON object : View

Products Affected

mindwerks

  • wildmidi
CWE
CWE-125

Out-of-bounds Read