Vulnerability Details CVE-2007-6720
libmikmod 3.1.9 through 3.2.0, as used by MikMod, SDL-mixer, and possibly other products, relies on the channel count of the last loaded song, rather than the currently playing song, for certain playback calculations, which allows user-assisted attackers to cause a denial of service (application crash) by loading multiple songs (aka MOD files) with different numbers of channels.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.6%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2007-6720
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.10-1
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.10-2
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.10-3
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.10-4
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.10-5
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.11-1
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.11-2
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.11-3
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.11-4
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.11-5
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.11-6
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.12
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.9-1
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.9-2
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.9-3
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.9-4
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.9-5
-
cpe:2.3:a:igno_saitz:libmikmod:3.1.9-6
-
cpe:2.3:a:igno_saitz:libmikmod:3.2.0