Off-by-One Error in libmodplug Affects Multiple Platforms
CVE-2011-2914
Currently unrated
What is CVE-2011-2914?
The identified vulnerability in libmodplug stems from an off-by-one error in the CSoundFile::ReadDSM function located in src/load_dms.cpp. This flaw may allow attackers to corrupt memory and potentially execute arbitrary code if a specially crafted DSM file is processed. Users of affected versions prior to 0.8.8.4 are strongly advised to update their software to mitigate these risks, as exploitation can occur through the manipulation of a file containing a large number of samples.
