6.8
CVSSv2

CVE-2011-2911

Published: 07/06/2012 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the CSoundFile::ReadWav function in src/load_wav.cpp in libmodplug prior to 0.8.8.4 allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a crafted WAV file, which triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

konstanty bialkowski libmodplug 0.8.5

konstanty bialkowski libmodplug 0.8.7

konstanty bialkowski libmodplug

konstanty bialkowski libmodplug 0.8.4

konstanty bialkowski libmodplug 0.8.8.1

konstanty bialkowski libmodplug 0.8.8.2

konstanty bialkowski libmodplug 0.8.8

konstanty bialkowski libmodplug 0.8

konstanty bialkowski libmodplug 0.8.6

Vendor Advisories

libmodplug could be made to crash or run programs as your login if it opened a specially crafted file ...