An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/schismtracker/schismtracker/issues/201 | third party advisory issue tracking exploit |
https://github.com/schismtracker/schismtracker/releases/tag/20190805 | release notes |
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00072.html | vendor advisory mailing list third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00083.html | vendor advisory mailing list third party advisory |