6.8
CVSSv2

CVE-2013-4233

Published: 16/09/2013 Updated: 25/09/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and previous versions allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC file, which triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

konstanty_bialkowski libmodplug 0.8.8

konstanty_bialkowski libmodplug 0.8.7

konstanty_bialkowski libmodplug 0.8.6

konstanty_bialkowski libmodplug 0.8.5

konstanty_bialkowski libmodplug 0.8.4

konstanty_bialkowski libmodplug

konstanty_bialkowski libmodplug 0.8.8.2

konstanty_bialkowski libmodplug 0.8

konstanty_bialkowski libmodplug 0.8.8.3

konstanty_bialkowski libmodplug 0.8.8.1

debian debian_linux 7.0

debian debian_linux 6.0

Vendor Advisories

Debian Bug report logs - #719462 libmodplug: CVE-2013-4233 CVE-2013-4234 Package: libmodplug; Maintainer for libmodplug is Stephen Kitt <skitt@debianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 12 Aug 2013 06:33:02 UTC Severity: grave Tags: security Fixed in versions libmodplug/1:0884-4, lib ...