QID 671093
Date Published: 2021-11-29
QID 671093: EulerOS Security Update for libmtp (EulerOS-SA-2019-2452)
This package provides a software library for communicating with mtp (media transfer protocol) media players, typically audio players, video players etc.
Security fix(es): an integer overflow vulnerability in the ptp_unpack_eos_customfuncex function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a usb cable.(cve-2017-9831) an integer overflow vulnerability in ptp-pack.c (ptp_unpack_opl function) of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a usb cable.(cve-2017-9832)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
CVEs related to QID 671093
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2019-2452 | EulerOS V2.0SP2 |
|