ALT-PU-2021-3029-1
Package milkytracker updated to version 1.03.00-alt1_1 for branch sisyphus in task 286909.
Closed vulnerabilities
Published: 2019-08-01
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-14464
XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- https://github.com/milkytracker/MilkyTracker/issues/184
- https://github.com/milkytracker/MilkyTracker/issues/184
- [debian-lts-announce] 20191021 [SECURITY] [DLA 1961-1] milkytracker security update
- [debian-lts-announce] 20191021 [SECURITY] [DLA 1961-1] milkytracker security update
- [debian-lts-announce] 20200727 [SECURITY] [DLA 2292-1] milkytracker security update
- [debian-lts-announce] 20200727 [SECURITY] [DLA 2292-1] milkytracker security update
- FEDORA-2019-3d5f61419f
- FEDORA-2019-3d5f61419f
- FEDORA-2019-04babe66b5
- FEDORA-2019-04babe66b5
- USN-4499-1
- USN-4499-1
Published: 2019-08-01
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-14496
LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflow.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- https://github.com/milkytracker/MilkyTracker/issues/183
- https://github.com/milkytracker/MilkyTracker/issues/183
- [debian-lts-announce] 20191021 [SECURITY] [DLA 1961-1] milkytracker security update
- [debian-lts-announce] 20191021 [SECURITY] [DLA 1961-1] milkytracker security update
- [debian-lts-announce] 20200727 [SECURITY] [DLA 2292-1] milkytracker security update
- [debian-lts-announce] 20200727 [SECURITY] [DLA 2292-1] milkytracker security update
- USN-4499-1
- USN-4499-1
Published: 2019-08-01
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-14497
ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based buffer overflow.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- https://github.com/milkytracker/MilkyTracker/issues/182
- https://github.com/milkytracker/MilkyTracker/issues/182
- [debian-lts-announce] 20191021 [SECURITY] [DLA 1961-1] milkytracker security update
- [debian-lts-announce] 20191021 [SECURITY] [DLA 1961-1] milkytracker security update
- [debian-lts-announce] 20200727 [SECURITY] [DLA 2292-1] milkytracker security update
- [debian-lts-announce] 20200727 [SECURITY] [DLA 2292-1] milkytracker security update
- USN-4499-1
- USN-4499-1
Published: 2020-07-06
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-15569
PlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in the PlayerGeneric destructor.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- https://github.com/milkytracker/MilkyTracker/commit/7afd55c42ad80d01a339197a2d8b5461d214edaf
- https://github.com/milkytracker/MilkyTracker/commit/7afd55c42ad80d01a339197a2d8b5461d214edaf
- [debian-lts-announce] 20200727 [SECURITY] [DLA 2292-1] milkytracker security update
- [debian-lts-announce] 20200727 [SECURITY] [DLA 2292-1] milkytracker security update