Off-by-one Error in libmodplug Affects Multiple Linux Distributions
CVE-2011-2913

Currently unrated

Key Information:

Vendor
CVE Published:
7 June 2012

What is CVE-2011-2913?

An off-by-one error in the CSoundFile::ReadAMS function within the libmodplug library prior to version 0.8.8.4 allows remote attackers to exploit crafted AMS files to trigger stack memory corruption. This vulnerability poses a risk of denial of service and may allow the execution of arbitrary code, exploiting the library's handling of specific input data with an excessive number of samples. Users and administrators are advised to update to the fixed version to mitigate potential threats.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.