Computer Security
[EN] securityvulns.ru no-pyccku


libmodplug security vulnerabilities
Published:09.09.2013
Source:
SecurityVulns ID:13267
Type:library
Threat Level:
5/10
Description:Few code execution possibilities
Affected:LIBMODPLUG : libmodplug 0.8
CVE:CVE-2013-4234 (Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted ABC.)
 CVE-2013-4233 (Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC file, which triggers a heap-based buffer overflow.)
Original documentdocumentDEBIAN, [SECURITY] [DSA 2751-1] libmodplug security update (09.09.2013)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod