PT-2013-1090 · Modplug+2 · Libmodplug+2

Publicado

2013-09-13

·

Atualizado

2018-05-28

·

CVE-2013-4234

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libmodplug versions 0.8.8.4 and earlier
Description The issue is related to multiple heap-based buffer overflows in the abc MIDI drum and abc MIDI gchord functions in load abc.cpp. This can allow remote attackers to cause a denial of service, resulting in memory corruption and crash, and possibly execute arbitrary code via a crafted ABC file. The vulnerability can be exploited remotely, potentially leading to disruptions in confidentiality, integrity, and availability of protected information.
Recommendations For libmodplug versions 0.8.8.4 and earlier, consider updating to a version later than 0.8.8.4 to resolve the issue. As a temporary workaround, consider restricting access to the abc MIDI drum and abc MIDI gchord functions in load abc.cpp to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2128
BDU:2015-03019
BDU:2015-09742
CVE-2013-4234
DSA-2751-1
MGASA-2013-0271
OPENSUSE-SU-2024:10514-1
SUSE-SU-2018:1441-1

Produtos afetados

Alt Linux
Suse
Libmodplug