An integer overflow vulnerability in the ptpunpackEOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "1.1.13-1", "binary_name": "libmtp-common" }, { "binary_version": "1.1.13-1", "binary_name": "libmtp-dbg" }, { "binary_version": "1.1.13-1", "binary_name": "libmtp-dev" }, { "binary_version": "1.1.13-1", "binary_name": "libmtp-doc" }, { "binary_version": "1.1.13-1", "binary_name": "libmtp-runtime" }, { "binary_version": "1.1.13-1", "binary_name": "libmtp-runtime-dbgsym" }, { "binary_version": "1.1.13-1", "binary_name": "libmtp9" }, { "binary_version": "1.1.13-1", "binary_name": "mtp-tools" }, { "binary_version": "1.1.13-1", "binary_name": "mtp-tools-dbgsym" } ] }