PT-2013-1089 · Gentoo Linux+2 · Libmodplug+2

Florian

·

Published

2013-09-13

·

Updated

2018-05-28

·

CVE-2013-4233

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libmodplug versions prior to 0.8.8.5
Description The issue affects the libmodplug package in Gentoo Linux and Debian GNU/Linux operating systems. It involves multiple vulnerabilities that can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Specifically, an integer overflow in the abc set parts function in load abc.cpp can cause a denial of service and possibly allow the execution of arbitrary code via a crafted P header in an ABC file, triggering a heap-based buffer overflow.
Recommendations For versions prior to 0.8.8.5, update to version 0.8.8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the abc set parts function in load abc.cpp to minimize the risk of exploitation. Avoid using crafted P headers in ABC files until the issue is resolved.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2128
BDU:2015-03019
BDU:2015-09742
CVE-2013-4233
DSA-2751-1
MGASA-2013-0271
OPENSUSE-SU-2024:10514-1
SUSE-SU-2018:1441-1
SUSE-SU-2018_1441-1

Affected Products

Alt Linux
Suse
Libmodplug