CVE-2019-14381: Null Pointer Dereference
libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument to an empty instrument note map slot.
libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument to an empty instrument note map slot.
Systems that process attacker-controlled module files with affected libopenmpt versions are exposed to a remote denial of service. The CVSS vector indicates exploitation requires no privileges or user interaction and can be performed over a network.
An attacker needs to cause affected libopenmpt to process a module containing a portamento from an OPL instrument to an empty instrument note-map slot. Successful exploitation crashes the process through a NULL pointer dereference; the stated impact is availability only.
Update libopenmpt to version 0.4.3 or later, since versions before 0.4.3 are identified as affected.