MilkyTracker v1.03.00 was discovered to contain a stack overflow via the component LoaderXM::load. This vulnerability is triggered when the program is supplied a crafted XM module file.
{ "vanir_signatures": [ { "target": { "file": "src/milkyplay/LoaderXM.cpp" }, "digest": { "threshold": 0.9, "line_hashes": [ "92762678729644534731041799942737680000", "263997541143629577749552266977049635344", "224676694526586997915366558330786479696", "113720897472328604541739210501823761945" ] }, "signature_type": "Line", "source": "https://github.com/milkytracker/milkytracker/commit/3a5474f9102cbdc10fbd9e7b1b2c8d3f3f45d91b", "deprecated": false, "id": "CVE-2022-34927-2af757c9", "signature_version": "v1" }, { "target": { "file": "src/milkyplay/LoaderXM.cpp", "function": "LoaderXM::load" }, "digest": { "function_hash": "154008910926743438524962085660973975776", "length": 16512.0 }, "signature_type": "Function", "source": "https://github.com/milkytracker/milkytracker/commit/3a5474f9102cbdc10fbd9e7b1b2c8d3f3f45d91b", "deprecated": false, "id": "CVE-2022-34927-cb042e6a", "signature_version": "v1" } ] }