CVE-2017-11662
HIGHWildMIDI 0.4.2 - Denial of Service via Crafted MIDI File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-11662. PoCs published by qflb.wu.
AI-analyzed exploit summary The exploit demonstrates multiple denial-of-service vulnerabilities in WildMIDI 0.4.2, specifically invalid memory reads leading to application crashes via crafted MIDI files. The PoC includes debug information and stack traces showing segmentation faults in functions like _WM_SetupMidiEvent and _WM_ParseNewMidi.
Description
The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.
Exploits (1)
The exploit demonstrates multiple denial-of-service vulnerabilities in WildMIDI 0.4.2, specifically invalid memory reads leading to application crashes via crafted MIDI files. The PoC includes debug information and stack traces showing segmentation faults in functions like _WM_SetupMidiEvent and _WM_ParseNewMidi.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H