PT-2009-6725 · Modplug · Libmodplug
Manfred Tremmel
+1
·
Published
1970-01-01
·
Updated
2009-08-08
·
CVE-2009-1513
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libmodplug versions prior to 0.8.7
Description
The issue is related to a buffer overflow in the PATinst function in src/load pat.cpp, which can be exploited by remote attackers to cause a denial of service and possibly execute arbitrary code via a long instrument name. The vulnerability can lead to a violation of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely.
Recommendations
For versions prior to 0.8.7, update to version 0.8.7 or later to resolve the issue. As a temporary workaround, consider restricting the use of the PATinst function in src/load pat.cpp to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libmodplug