PT-2009-6725 · Modplug · Libmodplug

Manfred Tremmel

+1

·

Publicado

1970-01-01

·

Atualizado

2009-08-08

·

CVE-2009-1513

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libmodplug versions prior to 0.8.7
Description The issue is related to a buffer overflow in the PATinst function in src/load pat.cpp, which can be exploited by remote attackers to cause a denial of service and possibly execute arbitrary code via a long instrument name. The vulnerability can lead to a violation of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely.
Recommendations For versions prior to 0.8.7, update to version 0.8.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of the PATinst function in src/load pat.cpp to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04117
BDU:2015-04118
BDU:2015-09392
CVE-2009-1513
DSA-1850-1

Produtos afetados

Libmodplug