6.8
CVSSv2

CVE-2009-1513

Published: 04/05/2009 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the PATinst function in src/load_pat.cpp in libmodplug prior to 0.8.7 allows user-assisted remote malicious users to cause a denial of service and possibly execute arbitrary code via a long instrument name.

Vulnerable Product Search on Vulmon Subscribe to Product

konstanty bialkowski libmodplug 0.8.5

konstanty bialkowski libmodplug

konstanty bialkowski libmodplug 0.8.4

konstanty bialkowski libmodplug 0.8

Vendor Advisories

It was discovered that libmodplug did not correctly handle certain parameters when parsing MED media files If a user or automated system were tricked into opening a crafted MED file, an attacker could execute arbitrary code with privileges of the user invoking the program (CVE-2009-1438) ...
Several vulnerabilities have been discovered in libmodplug, the shared libraries for mod music based on ModPlug The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-1438 It was discovered that libmodplug is prone to an integer overflow when processing a MED file with a crafted song comment or song name CVE ...