Sorry for the delayed response.
First, to address the issue, I consulted with the developer and confirmed that 
the program has been patched with these commits:
- https://sourceforge.net/p/abc2midiu/code/22/
- https://sourceforge.net/p/abc2midiu/code/23/

However, the developer of abc2midi is currently refactoring most of the code.
The following is the latest version of the abc2midi program, which provides the 
same functionality:
- https://sourceforge.net/projects/abc2midiu/

I recommend updating to the latest patched version to address the bug.
Please also note that CVE-2024-54895 has been assigned for this issue for your 
reference.

Thank you.

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-54895

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2086695

Title:
  heap buffer overflow in getword

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/abcmidi/+bug/2086695/+subscriptions


-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to