PT-2006-1072 · Libmodplug Team+2 · Libmodplug+2

Jan Lieskovsky

·

Published

2006-08-17

·

Updated

2018-10-17

·

CVE-2006-4192

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: OpenMPT versions 1.17.02.43 and earlier libmodplug versions 0.8 and earlier
Description: The issue allows user-assisted remote attackers to execute arbitrary code via long strings in ITP files used by the CSoundFile::ReadITProject function in soundlib/Load it.cpp and crafted modules used by the CSoundFile::ReadSample function in soundlib/Sndfile.cpp. This can be demonstrated by crafted AMF files. The vulnerability may lead to disruption of confidentiality, integrity, and availability of protected information and can be exploited remotely.
Recommendations: For OpenMPT versions 1.17.02.43 and earlier, consider disabling the CSoundFile::ReadITProject and CSoundFile::ReadSample functions until a patch is available. For libmodplug versions 0.8 and earlier, restrict access to the soundlib/Load it.cpp and soundlib/Sndfile.cpp modules to minimize the risk of exploitation. Avoid using crafted ITP files and modules in the affected products until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09528
CVE-2006-4192
RHSA-2011:0477
RHSA-2011_0477

Affected Products

Openmpt
Red Hat
Libmodplug