9.3
CVSSv2

CVE-2010-2546

Published: 05/08/2010 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple heap-based buffer overflows in loaders/load_it.c in libmikmod, possibly 3.1.12, might allow remote malicious users to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file, related to panpts, pitpts, and IT_ProcessEnvelope. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3995.

Vulnerable Product Search on Vulmon Subscribe to Product

raphael assenat libmikmod 3.1.12

Vendor Advisories

It was discovered that libMikMod incorrectly handled songs with different channel counts If a user were tricked into opening a crafted song file, an attacker could cause a denial of service (CVE-2007-6720) ...
Debian Bug report logs - #575742 CVE-2009-3995 CVE-2009-3996: Multiple heap-based buffer overflows Package: libmikmod; Maintainer for libmikmod is Stephen Kitt <skitt@debianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Sun, 28 Mar 2010 21:12:01 UTC Severity: serious Tags: patch, security Fixed in ...