Heap data exposure via out-of-bounds MTM read
Published Feb 17, 2023 · Updated Mar 18, 2025
Out-of-bounds read in Schism Tracker 20200412 allows context-dependent attackers to expose heap data through a crafted MTM file. In fmt/mtm.c, fmt_mtm_load_song accesses trackdata[n] after n reaches the allocated track-data boundary, and the patch removes this unused access. The public reproducer requires opening an attacker-supplied MTM module; the observed consequence is an eight-byte heap read that remains silent without memory instrumentation.
Summary
What happened
Out-of-bounds read in Schism Tracker 20200412 allows context-dependent attackers to expose heap data through a crafted MTM file. In fmt/mtm.c, fmt_mtm_load_song accesses trackdata[n] after n reaches the allocated track-data boundary, and the patch removes this unused access. The public reproducer requires opening an attacker-supplied MTM module; the observed consequence is an eight-byte heap read that remains silent without memory instrumentation.
The record
- CVE
- CVE-2021-32419
- Published
- Feb 17, 2023
- Updated
- Mar 18, 2025
- Vendor
- Unknown vendor
- Product
- Unknown product
- Classifications
- CWE-787, T1204.002
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Feb 17, 2023CVE publishedPublication date reported by the CVE source.
- Mar 18, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
What conditions does exploitation require?
What is affected?
Affected products and versions are unavailable in this record.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- testx.mtm reproducerproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo