PT-2013-1090 · Modplug+2 · Libmodplug+2

Published

2013-09-13

·

Updated

2018-05-28

·

CVE-2013-4234

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libmodplug versions 0.8.8.4 and earlier
Description The issue is related to multiple heap-based buffer overflows in the abc MIDI drum and abc MIDI gchord functions in load abc.cpp. This can allow remote attackers to cause a denial of service, resulting in memory corruption and crash, and possibly execute arbitrary code via a crafted ABC file. The vulnerability can be exploited remotely, potentially leading to disruptions in confidentiality, integrity, and availability of protected information.
Recommendations For libmodplug versions 0.8.8.4 and earlier, consider updating to a version later than 0.8.8.4 to resolve the issue. As a temporary workaround, consider restricting access to the abc MIDI drum and abc MIDI gchord functions in load abc.cpp to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2128
BDU:2015-03019
BDU:2015-09742
CVE-2013-4234
DSA-2751-1
MGASA-2013-0271
OPENSUSE-SU-2024:10514-1
SUSE-SU-2018:1441-1

Affected Products

Alt Linux
Suse
Libmodplug