CVE-2019-14383: Medium severity libopenmpt0 vulnerability
J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
Systems using libopenmpt before version 0.4.2 are affected when they parse J2B files. The listed software includes openSUSE Leap and OpenMPT libopenmpt.
An attacker needs to cause a target to parse a crafted J2B file. No privileges are required, but user interaction is required according to the CVSS vector.
Successful exploitation causes an assertion failure during file parsing when debug STLs are used, resulting in a denial of service. The provided CVSS vector indicates no confidentiality or integrity impact.
Apply the available patch and update libopenmpt to version 0.4.2 or later. If patching cannot happen immediately, avoid parsing untrusted J2B files in affected environments.