6.8
CVSSv2

CVE-2011-2915

Published: 07/06/2012 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Off-by-one error in the CSoundFile::ReadAMS2 function in src/load_ams.cpp in libmodplug prior to 0.8.8.4 allows remote malicious users to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted AMS file with a large number of instruments.

Vulnerable Product Search on Vulmon Subscribe to Product

konstanty bialkowski libmodplug 0.8.5

konstanty bialkowski libmodplug 0.8.7

konstanty bialkowski libmodplug

konstanty bialkowski libmodplug 0.8.4

konstanty bialkowski libmodplug 0.8.8.1

konstanty bialkowski libmodplug 0.8.8.2

konstanty bialkowski libmodplug 0.8.8

konstanty bialkowski libmodplug 0.8

konstanty bialkowski libmodplug 0.8.6

Vendor Advisories

libmodplug could be made to crash or run programs as your login if it opened a specially crafted file ...