Vulnerability Description
An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libmtp Project | Libmtp | 1.1.12 |
Related Weaknesses (CWE)
References
- https://lists.debian.org/debian-lts-announce/2020/04/msg00003.html
- https://sourceforge.net/p/libmtp/mailman/message/35735992/Issue TrackingMailing ListPatch
- https://lists.debian.org/debian-lts-announce/2020/04/msg00003.html
- https://sourceforge.net/p/libmtp/mailman/message/35735992/Issue TrackingMailing ListPatch
FAQ
What is CVE-2017-9831?
CVE-2017-9831 is a vulnerability with a CVSS score of 6.8 (MEDIUM). An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds m...
How severe is CVE-2017-9831?
CVE-2017-9831 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9831?
Check the references section above for vendor advisories and patch information. Affected products include: Libmtp Project Libmtp.