AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::_bmfconvert_stream() in bmf.cpp.
{ "urgency": "not yet assigned" }