Off-by-One Error in libmodplug Affects Multiple Vendors
CVE-2011-2915

Currently unrated

Key Information:

Vendor
CVE Published:
7 June 2012

What is CVE-2011-2915?

An off-by-one error exists in the CSoundFile::ReadAMS2 function of the libmodplug library prior to version 0.8.8.4. This flaw allows remote attackers to manipulate crafted AMS files containing a large number of instruments, potentially leading to memory corruption. In the worst-case scenario, such exploitation could enable an attacker to execute arbitrary code on the affected system, thereby compromising its integrity and security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.