Vulnerability CVE-2018-17825: Information
Description
An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TL_TABLE, SIN_TABLE, AMS_TABLE, and VIB_TABLE.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: HIGH (7.5)
Vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| libadplug | sisyphus | 2.2.1-alt3 | 2.3.3-alt1.git104.g66b19f6 | ALT-PU-2019-2765-1 | 237968 | Fixed |
| libadplug | p11 | 2.2.1-alt3 | 2.3.3-alt1.git104.g66b19f6 | ALT-PU-2019-2765-1 | 237968 | Fixed |
| libadplug | p10 | 2.2.1-alt3 | 2.2.1-alt3 | ALT-PU-2019-2765-1 | 237968 | Fixed |
| libadplug | p9 | 2.2.1-alt3 | 2.2.1-alt3 | ALT-PU-2019-2774-1 | 238027 | Fixed |
| libadplug | c10f2 | 2.2.1-alt3 | 2.2.1-alt3 | ALT-PU-2019-2765-1 | 237968 | Fixed |
| libadplug | c9f2 | 2.2.1-alt3 | 2.2.1-alt3 | ALT-PU-2019-2774-1 | 238027 | Fixed |