An integer overflow vulnerability in ptp-pack.c (ptpunpackOPL function) of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.
{ "binaries": [ { "binary_version": "1.1.10-2ubuntu1", "binary_name": "libmtp-common" }, { "binary_version": "1.1.10-2ubuntu1", "binary_name": "libmtp-dev" }, { "binary_version": "1.1.10-2ubuntu1", "binary_name": "libmtp-runtime" }, { "binary_version": "1.1.10-2ubuntu1", "binary_name": "libmtp9" }, { "binary_version": "1.1.10-2ubuntu1", "binary_name": "mtp-tools" } ] }