Impact
An out-of-bounds write was discovered in the TXT file parser of vgmstream. The flaw occurs in the parse_params/txtp_parse function within src/meta/txtp_parser.c and allows an attacker to write beyond the bounds of a buffer, potentially corrupting memory or causing a crash. Because the vulnerable code processes externally supplied TXT files, the attack can be remote by providing malicious files over a network or other remote channels.
Affected Systems
All released builds of vgmstream up to revision r2117 are affected. The vulnerability is present in all branches that include the old implementation of the TXT file handler until the patch commit 4669d37a6af94866f6f0628678f9f90d46954e8b is applied, which updates the library to r2118 or later.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, but the advisory explicitly states that the attacker may launch the attack remotely, raising concern for deployments that accept untrusted input. The vulnerability is not listed in the CISA KEV catalog, so no large-scale exploitation is known. If exploited, the out-of-bounds condition could lead to denial of service or, with advanced techniques, potential code execution through memory corruption.
OpenCVE Enrichment