Impact
The flaw resides in the ABC Music Format parser of libmodplug, specifically within the abc_add_gchord routine in src/load_abc.cpp. Manipulating the behaviors of this routine can trigger excessive use of system resources, leading to a denial‑of‑service condition. The weakness is identified as a resource exhaustion problem (CWE‑400) and a potential improper handling of edge cases (CWE‑404). While no exploit code is publicly released, the description states that the attack can be initiated remotely, implying that a malicious ABC file could be supplied to a vulnerable system without local access.
Affected Systems
The affected software is Konstanty Bialkowski’s libmodplug library, version 0.8.9.1 or earlier. The vulnerability impacts any build that includes the ABC Music Format parser module and does not provide an updated code path to mitigate the resource consumption issue.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the medium severity range. EPSS data is not available, and the flaw is not catalogued in CISA’s KEV list, suggesting that there has been no confirmed, widespread exploitation to date. Nevertheless, an attacker who can supply a crafted ABC file over the network can trigger excessive CPU or memory usage, potentially disrupting service availability. The lack of available patch information increases the risk for systems that remain on the vulnerable version.
OpenCVE Enrichment