6.8
CVSSv2

CVE-2011-2913

Published: 07/06/2012 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Off-by-one error in the CSoundFile::ReadAMS function in src/load_ams.cpp in libmodplug prior to 0.8.8.4 allows remote malicious users to cause a denial of service (stack memory corruption) and possibly execute arbitrary code via a crafted AMS file with a large number of samples.

Vulnerable Product Search on Vulmon Subscribe to Product

konstanty bialkowski libmodplug 0.8.5

konstanty bialkowski libmodplug 0.8.7

konstanty bialkowski libmodplug

konstanty bialkowski libmodplug 0.8.4

konstanty bialkowski libmodplug 0.8.8.1

konstanty bialkowski libmodplug 0.8.8.2

konstanty bialkowski libmodplug 0.8.8

konstanty bialkowski libmodplug 0.8

konstanty bialkowski libmodplug 0.8.6

Vendor Advisories

libmodplug could be made to crash or run programs as your login if it opened a specially crafted file ...