CVE-2007-6731
Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 14.07% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- claudio matsuoka/extended module player
- Source
- cve@mitre.org
References
- http://aluigi.altervista.org/adv/xmpbof-adv.txtExploit
- http://www.securityfocus.com/bid/27047Exploit
- http://www.vupen.com/english/advisories/2008/0009Vendor Advisory
- http://aluigi.altervista.org/adv/xmpbof-adv.txtExploit
- http://www.securityfocus.com/bid/27047Exploit
- http://www.vupen.com/english/advisories/2008/0009Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.