Menu

#27 overflow bugs in abc2midi

open
nobody
None
5
2024-11-06
2024-11-06
No

Hi,
Thank you so much for maintaining such a good open source.
I found some bugs in the abc2midi program that could be a potential security threat.
Here are the 7 types of bug reports I found.
* https://bugs.launchpad.net/ubuntu/+source/abcmidi/+bug/2086698
* https://bugs.launchpad.net/ubuntu/+source/abcmidi/+bug/2086697
* https://bugs.launchpad.net/ubuntu/+source/abcmidi/+bug/2086696
* https://bugs.launchpad.net/ubuntu/+source/abcmidi/+bug/2086695
* https://bugs.launchpad.net/ubuntu/+source/abcmidi/+bug/2086693
* https://bugs.launchpad.net/ubuntu/+source/abcmidi/+bug/2086692
* https://bugs.launchpad.net/ubuntu/+source/abcmidi/+bug/2086689

The report used the source code provided by Ubuntu[1], but the error was also reproduced when using the latest version of abc2midi source code[2] uploaded to GitHub.

[1] https://git.launchpad.net/ubuntu/+source/abcmidi
[2] https://github.com/sshlien/abcmidi

I'll attach the poc file that causes the error to each report so you can check it out.

Thanks.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB