Bugzilla – Bug 1045916
VUL-1: CVE-2017-9831: libmtp: Integer overflow in ptp_unpack_EOS_CustomFuncEx allows attackers to cause DoS or potentially RCE
Last modified: 2020-06-29 06:29:15 UTC
CVE-2017-9831 An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-9831 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9831 http://www.cvedetails.com/cve/CVE-2017-9831/ https://sourceforge.net/p/libmtp/mailman/message/35735992/