CVE-2019-14524: Buffer Overflow
Published Aug 2, 2019
·Updated
An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmtmtmloadsong in fmt/mtm.c, a different vulnerability than CVE-2019-14465.
Affected Software
5 affected components
Schismtracker Schism Tracker<=20190722
openSUSE Backports=sle-15
openSUSE Backports=sle-15-sp1
openSUSE Leap=15.0
openSUSE Leap=15.1
Event History
Aug 2, 2019
CVE Published
via MITRE·11:18 AM
Data Sourced
via MITRE·11:18 AM
Description
Frequently Asked Questions
1
What is CVE-2019-14524?
CVE-2019-14524 is a vulnerability discovered in Schism Tracker that allows for a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c.
2
How severe is CVE-2019-14524?
CVE-2019-14524 has a severity score of 7.8 out of 10.
3
What software versions are affected by CVE-2019-14524?
Schism Tracker version 20190722 is affected by CVE-2019-14524.
4
How can I fix CVE-2019-14524?
To fix CVE-2019-14524, update to a version of Schism Tracker that is not vulnerable to this issue.
5
Where can I find more information about CVE-2019-14524?
You can find more information about CVE-2019-14524 in the Schism Tracker GitHub issue tracker and the OpenSUSE security announcement.