AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://github.com/adplug/adplug/issues/91 | patch third party advisory exploit |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3PW6PLDTPSQQRHKTU2FB72SUB4Q66NE/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q32A64R2APAC5PXIMSYIEFDQX5AD4GAS/ | vendor advisory |