CVE-2007-6731
EPSS 14.1%
Description
Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow.
How to fix CVE-2007-6731
To remediate CVE-2007-6731, upgrade the affected package to a fixed version below.
- Debian/xmp—upgrade to 2.6.1-1 or later
Is CVE-2007-6731 being exploited?
Moderate — EPSS is 14.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.6.1-1