{"id":"GHSA-874w-m2v2-mj64","summary":"Double Free in Adplug","details":"AdPlug 2.3.1 has a double free in the `Cu6mPlayer` class in `u6m.h`.","aliases":["CVE-2019-15151"],"modified":"2024-02-21T05:32:44.011647Z","published":"2021-03-29T20:48:45Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-03-23T20:51:24Z","nvd_published_at":"2019-08-18T21:15:00Z","cwe_ids":["CWE-415"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15151"},{"type":"WEB","url":"https://github.com/adplug/adplug/issues/91"},{"type":"WEB","url":"https://github.com/adplug/adplug/commit/1a282a486a8e33fef3e15998bf6408d3515dc07e"},{"type":"WEB","url":"https://github.com/miller-alex/adplug/commit/8abb9328bf27dcbdafc67ade3e75af0ffd8f7633"},{"type":"PACKAGE","url":"https://github.com/adplug/adplug"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q32A64R2APAC5PXIMSYIEFDQX5AD4GAS"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U3PW6PLDTPSQQRHKTU2FB72SUB4Q66NE"}],"affected":[{"package":{"name":"adplug","ecosystem":"NuGet","purl":"pkg:nuget/adplug"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.3"}]}],"versions":["2.3.0-beta10","2.3.0-beta100","2.3.0-beta105","2.3.0-beta108","2.3.0-beta114","2.3.0-beta116","2.3.0-beta118","2.3.0-beta119","2.3.0-beta120","2.3.0-beta123","2.3.0-beta125","2.3.0-beta126","2.3.0-beta127","2.3.0-beta128","2.3.0-beta129","2.3.0-beta132","2.3.0-beta134","2.3.0-beta135","2.3.0-beta136","2.3.0-beta137","2.3.0-beta138","2.3.0-beta14","2.3.0-beta140","2.3.0-beta145","2.3.0-beta146","2.3.0-beta153","2.3.0-beta155","2.3.0-beta156","2.3.0-beta16","2.3.0-beta161","2.3.0-beta17","2.3.0-beta172","2.3.0-beta173","2.3.0-beta18","2.3.0-beta186","2.3.0-beta19","2.3.0-beta190","2.3.0-beta208","2.3.0-beta21","2.3.0-beta22","2.3.0-beta221","2.3.0-beta222","2.3.0-beta223","2.3.0-beta228","2.3.0-beta229","2.3.0-beta231","2.3.0-beta232","2.3.0-beta233","2.3.0-beta241","2.3.0-beta245","2.3.0-beta246","2.3.0-beta254","2.3.0-beta266","2.3.0-beta29","2.3.0-beta31","2.3.0-beta33","2.3.0-beta43","2.3.0-beta44","2.3.0-beta45","2.3.0-beta46","2.3.0-beta47","2.3.0-beta52","2.3.0-beta54","2.3.0-beta59","2.3.0-beta62","2.3.0-beta86","2.3.1","2.3.2-beta272","2.3.2-beta274","2.3.2-beta275","2.3.2-beta278","2.3.2-beta279","2.3.2-beta295","2.3.2-beta296","2.3.2-beta298","2.3.2-beta302","2.3.2-beta305","2.3.2-beta307","2.3.2-beta313","2.3.2-beta314","2.3.2-beta329","2.3.3-beta334","2.3.3-beta335","2.3.3-beta336","2.3.3-beta337","2.3.3-beta338","2.3.3-beta339","2.3.3-beta344"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.3.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-874w-m2v2-mj64/GHSA-874w-m2v2-mj64.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}