An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TLTABLE, SINTABLE, AMSTABLE, and VIBTABLE.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "adplug-utils",
"binary_version": "2.2.1+dfsg3-1~build0.16.04.1"
},
{
"binary_name": "libadplug-2.2.1-0v5",
"binary_version": "2.2.1+dfsg3-1~build0.16.04.1"
},
{
"binary_name": "libadplug-dev",
"binary_version": "2.2.1+dfsg3-1~build0.16.04.1"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "adplug-utils",
"binary_version": "2.2.1+dfsg3-1~build0.18.04.1"
},
{
"binary_name": "libadplug-2.2.1-0v5",
"binary_version": "2.2.1+dfsg3-1~build0.18.04.1"
},
{
"binary_name": "libadplug-dev",
"binary_version": "2.2.1+dfsg3-1~build0.18.04.1"
}
]
}