PT-2013-1089 · Gentoo Linux+2 · Libmodplug+2

Florian

·

Publicado

2013-09-13

·

Atualizado

2018-05-28

·

CVE-2013-4233

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libmodplug versions prior to 0.8.8.5
Description The issue affects the libmodplug package in Gentoo Linux and Debian GNU/Linux operating systems. It involves multiple vulnerabilities that can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, an integer overflow in the abc set parts function in load abc.cpp can cause a denial of service and possibly allow the execution of arbitrary code via a crafted P header in an ABC file, triggering a heap-based buffer overflow.
Recommendations For versions prior to 0.8.8.5, update to version 0.8.8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the abc set parts function in load abc.cpp to minimize the risk of exploitation. Avoid using crafted P headers in ABC files until the issue is resolved.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2128
BDU:2015-03019
BDU:2015-09742
CVE-2013-4233
DSA-2751-1
MGASA-2013-0271
OPENSUSE-SU-2024:10514-1
SUSE-SU-2018:1441-1
SUSE-SU-2018_1441-1

Produtos afetados

Alt Linux
Suse
Libmodplug