CVE-2018-6611: Openmpt Libopenmpt

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

soundlib/Load_stp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malformed STP file.

Affected products

  • Openmpt Libopenmpt: before 0.3.6 (fixed in 0.3.6)
  • Openmpt Openmpt: up to and including 1.27.04.00

Published 2018-02-04. Last modified 2026-06-17.