Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-26923

Опубликовано: 28 мар. 2023
Источник: debian
EPSS Низкий

Описание

Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arbitrary code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
musescoreremovedpackage
musescorenot-affectedbusterpackage
musescore2not-affectedpackage
musescore3fixed3.2.3+dfsg2-18package

Примечания

  • https://github.com/musescore/MuseScore/issues/16346

  • Vulnerability triggered only on Windows codepath

EPSS

Процентиль: 18%
0.00057
Низкий

Связанные уязвимости

CVSS3: 7
ubuntu
почти 3 года назад

Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arbitrary code.

CVSS3: 7
nvd
почти 3 года назад

Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arbitrary code.

CVSS3: 7
github
почти 3 года назад

Musescore 3.0 to 4.0.1 has a stack buffer overflow vulnerability that occurs when reading misconfigured midi files. If attacker can additional information, attacker can execute arbitrary code.

EPSS

Процентиль: 18%
0.00057
Низкий