CVE-2007-6732
EPSS 5.6%
Description
Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays.
How to fix CVE-2007-6732
To remediate CVE-2007-6732, upgrade the affected package to a fixed version below.
- Debian/xmp—upgrade to 2.6.1-1 or later
Is CVE-2007-6732 being exploited?
Moderate — EPSS is 5.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.6.1-1