{"id":"UBUNTU-CVE-2024-44866","details":"A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.","modified":"2026-05-20T16:18:23.200187055Z","published":"2025-03-17T19:15:00Z","upstream":["CVE-2024-44866"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-44866"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-44866"},{"type":"REPORT","url":"https://github.com/moonadon9/CVE_2024"},{"type":"REPORT","url":"https://musescore.org/ko/download/musescore.msi"}],"affected":[{"package":{"name":"musescore","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/musescore?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.2+dfsg-1","2.0.2+dfsg-2","2.0.2+dfsg-2build1","2.0.2+dfsg-2ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore","binary_version":"2.0.2+dfsg-2ubuntu0.1"},{"binary_name":"musescore-common","binary_version":"2.0.2+dfsg-2ubuntu0.1"},{"binary_name":"musescore-soundfont-gm","binary_version":"2.0.2+dfsg-2ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}},{"package":{"name":"musescore","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/musescore?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1.0+dfsg1-0.2","2.1.0+dfsg1-1","2.1.0+dfsg2-1","2.1.0+dfsg2-1build1","2.1.0+dfsg3-3","2.1.0+dfsg3-3build1"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore","binary_version":"2.1.0+dfsg3-3build1"},{"binary_name":"musescore-common","binary_version":"2.1.0+dfsg3-3build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}},{"package":{"name":"musescore","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/musescore?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.3+dfsg1-1","3.2.3+dfsg1-2","3.2.3+dfsg1-3","3.2.3+dfsg1-4","3.2.3+dfsg1-4build1"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore3","binary_version":"3.2.3+dfsg1-4build1"},{"binary_version":"3.2.3+dfsg1-4build1","binary_name":"musescore3-common"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}},{"package":{"name":"musescore2","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/musescore2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+dfsg4-15"],"ecosystem_specific":{"binaries":[{"binary_version":"2.3.2+dfsg4-15","binary_name":"musescore"},{"binary_name":"musescore-common","binary_version":"2.3.2+dfsg4-15"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}},{"package":{"name":"musescore3","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/musescore3?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.3+dfsg2-11"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore3","binary_version":"3.2.3+dfsg2-11"},{"binary_name":"musescore3-common","binary_version":"3.2.3+dfsg2-11"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}},{"package":{"name":"musescore2","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/musescore2?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+dfsg4-15","2.3.2+dfsg4-15build2","2.3.2+dfsg4-15build3"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore","binary_version":"2.3.2+dfsg4-15build3"},{"binary_name":"musescore-common","binary_version":"2.3.2+dfsg4-15build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}},{"package":{"name":"musescore3","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/musescore3?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.3+dfsg2-16","3.2.3+dfsg2-16build3","3.2.3+dfsg2-16build4","3.2.3+dfsg2-16build5"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore3","binary_version":"3.2.3+dfsg2-16build5"},{"binary_version":"3.2.3+dfsg2-16build5","binary_name":"musescore3-common"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}},{"package":{"name":"musescore2","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/musescore2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+dfsg4-15build3","2.3.2+dfsg4-16"],"ecosystem_specific":{"binaries":[{"binary_version":"2.3.2+dfsg4-16","binary_name":"musescore"},{"binary_name":"musescore-common","binary_version":"2.3.2+dfsg4-16"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}},{"package":{"name":"musescore3","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/musescore3?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.3+dfsg2-17","3.2.3+dfsg2-18","3.2.3+dfsg2-19"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore3","binary_version":"3.2.3+dfsg2-19"},{"binary_version":"3.2.3+dfsg2-19","binary_name":"musescore3-common"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}},{"package":{"name":"musescore2","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/musescore2?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+dfsg4-16","2.3.2+dfsg4-17"],"ecosystem_specific":{"binaries":[{"binary_name":"musescore","binary_version":"2.3.2+dfsg4-17"},{"binary_version":"2.3.2+dfsg4-17","binary_name":"musescore-common"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}},{"package":{"name":"musescore3","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/musescore3?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.3+dfsg2-19","3.2.3+dfsg2-21"],"ecosystem_specific":{"binaries":[{"binary_version":"3.2.3+dfsg2-21","binary_name":"musescore3"},{"binary_name":"musescore3-common","binary_version":"3.2.3+dfsg2-21"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-44866.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"},{"type":"Ubuntu","score":"medium"}]}