Vulnerability Description
Stack-based buffer overflow in the CSoundFile::ReadS3M function in src/load_s3m.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted S3M file with an invalid offset.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Konstanty Bialkowski | Libmodplug | <= 0.8.8.3 |
Related Weaknesses (CWE)
References
- http://jira.atheme.org/browse/AUDPLUG-394
- http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063786.htm
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066044.
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00019.html
- http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xm
- http://rhn.redhat.com/errata/RHSA-2011-1264.html
- http://secunia.com/advisories/45131Vendor Advisory
- http://secunia.com/advisories/45658Vendor Advisory
- http://secunia.com/advisories/45742Vendor Advisory
- http://secunia.com/advisories/45901Vendor Advisory
- http://secunia.com/advisories/46032Vendor Advisory
- http://secunia.com/advisories/46043Vendor Advisory
- http://secunia.com/advisories/46793Vendor Advisory
- http://secunia.com/advisories/48058Vendor Advisory
- http://secunia.com/advisories/48434Vendor Advisory
FAQ
What is CVE-2011-2912?
CVE-2011-2912 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Stack-based buffer overflow in the CSoundFile::ReadS3M function in src/load_s3m.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service and possibly execute arbitrary cod...
How severe is CVE-2011-2912?
CVE-2011-2912 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2912?
Check the references section above for vendor advisories and patch information. Affected products include: Konstanty Bialkowski Libmodplug.