{"id":"UBUNTU-CVE-2023-44428","details":"MuseScore CAP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MuseScore. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CAP files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20769.","modified":"2026-05-20T16:13:51.087528070Z","published":"2024-05-03T03:15:00Z","upstream":["CVE-2023-44428"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-44428"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-44428"},{"type":"REPORT","url":"https://www.zerodayinitiative.com/advisories/ZDI-23-1526/"}],"affected":[{"package":{"name":"musescore","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/musescore?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.2+dfsg-1","2.0.2+dfsg-2","2.0.2+dfsg-2build1","2.0.2+dfsg-2ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore","binary_version":"2.0.2+dfsg-2ubuntu0.1"},{"binary_version":"2.0.2+dfsg-2ubuntu0.1","binary_name":"musescore-common"},{"binary_version":"2.0.2+dfsg-2ubuntu0.1","binary_name":"musescore-soundfont-gm"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}},{"package":{"name":"musescore","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/musescore?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1.0+dfsg1-0.2","2.1.0+dfsg1-1","2.1.0+dfsg2-1","2.1.0+dfsg2-1build1","2.1.0+dfsg3-3","2.1.0+dfsg3-3build1"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore","binary_version":"2.1.0+dfsg3-3build1"},{"binary_version":"2.1.0+dfsg3-3build1","binary_name":"musescore-common"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}},{"package":{"name":"musescore","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/musescore?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.3+dfsg1-1","3.2.3+dfsg1-2","3.2.3+dfsg1-3","3.2.3+dfsg1-4","3.2.3+dfsg1-4build1"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore3","binary_version":"3.2.3+dfsg1-4build1"},{"binary_name":"musescore3-common","binary_version":"3.2.3+dfsg1-4build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}},{"package":{"name":"musescore2","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/musescore2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+dfsg4-15"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore","binary_version":"2.3.2+dfsg4-15"},{"binary_name":"musescore-common","binary_version":"2.3.2+dfsg4-15"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}},{"package":{"name":"musescore3","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/musescore3?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.3+dfsg2-11"],"ecosystem_specific":{"binaries":[{"binary_version":"3.2.3+dfsg2-11","binary_name":"musescore3"},{"binary_name":"musescore3-common","binary_version":"3.2.3+dfsg2-11"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}},{"package":{"name":"musescore2","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/musescore2?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+dfsg4-15","2.3.2+dfsg4-15build2","2.3.2+dfsg4-15build3"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore","binary_version":"2.3.2+dfsg4-15build3"},{"binary_name":"musescore-common","binary_version":"2.3.2+dfsg4-15build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}},{"package":{"name":"musescore3","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/musescore3?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.3+dfsg2-16","3.2.3+dfsg2-16build3","3.2.3+dfsg2-16build4","3.2.3+dfsg2-16build5"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore3","binary_version":"3.2.3+dfsg2-16build5"},{"binary_name":"musescore3-common","binary_version":"3.2.3+dfsg2-16build5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}},{"package":{"name":"musescore2","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/musescore2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+dfsg4-15build3","2.3.2+dfsg4-16"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore","binary_version":"2.3.2+dfsg4-16"},{"binary_name":"musescore-common","binary_version":"2.3.2+dfsg4-16"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}},{"package":{"name":"musescore3","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/musescore3?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.3+dfsg2-17","3.2.3+dfsg2-18","3.2.3+dfsg2-19"],"ecosystem_specific":{"binaries":[{"binary_version":"3.2.3+dfsg2-19","binary_name":"musescore3"},{"binary_name":"musescore3-common","binary_version":"3.2.3+dfsg2-19"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}},{"package":{"name":"musescore2","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/musescore2?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+dfsg4-16","2.3.2+dfsg4-17"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore","binary_version":"2.3.2+dfsg4-17"},{"binary_name":"musescore-common","binary_version":"2.3.2+dfsg4-17"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}},{"package":{"name":"musescore3","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/musescore3?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.3+dfsg2-19","3.2.3+dfsg2-21"],"ecosystem_specific":{"binaries":[{"binary_version":"3.2.3+dfsg2-21","binary_name":"musescore3"},{"binary_name":"musescore3-common","binary_version":"3.2.3+dfsg2-21"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-44428.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}