An integer overflow vulnerability in the ptpunpackEOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libmtp-common", "binary_version": "1.1.13-1" }, { "binary_name": "libmtp-dbg", "binary_version": "1.1.13-1" }, { "binary_name": "libmtp-dev", "binary_version": "1.1.13-1" }, { "binary_name": "libmtp-doc", "binary_version": "1.1.13-1" }, { "binary_name": "libmtp-runtime", "binary_version": "1.1.13-1" }, { "binary_name": "libmtp-runtime-dbgsym", "binary_version": "1.1.13-1" }, { "binary_name": "libmtp9", "binary_version": "1.1.13-1" }, { "binary_name": "mtp-tools", "binary_version": "1.1.13-1" }, { "binary_name": "mtp-tools-dbgsym", "binary_version": "1.1.13-1" } ] }