CVE-2018-6611: High severity libopenmpt0 vulnerability
soundlib/Loadstp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malformed STP file.
soundlib/Loadstp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malformed STP file.
Systems using OpenMPT through 1.27.04.00 or libopenmpt before 0.3.6 are affected when they process an STP file. The issue is reachable over the network only if an application exposes or receives attacker-supplied STP content.
An attacker needs to provide a malformed STP file and have a user or application process it. No attacker privileges are required, but user interaction is required according to the CVSS vector.
Apply the available patch by updating beyond the affected OpenMPT and libopenmpt versions. The provided remediation information does not specify a workaround for environments that cannot patch immediately.