Vulnerability Description
Off-by-one error in the CSoundFile::ReadAMS2 function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted AMS file with a large number of instruments.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Konstanty Bialkowski | Libmodplug | <= 0.8.8.3 |
Related Weaknesses (CWE)
References
- http://jira.atheme.org/browse/AUDPLUG-394
- http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063786.htm
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/066044.
- http://lists.opensuse.org/opensuse-security-announce/2011-08/msg00019.html
- http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xm
- http://rhn.redhat.com/errata/RHSA-2011-1264.html
- http://secunia.com/advisories/45131Vendor Advisory
- http://secunia.com/advisories/45658Vendor Advisory
- http://secunia.com/advisories/45742Vendor Advisory
- http://secunia.com/advisories/45901Vendor Advisory
- http://secunia.com/advisories/46032Vendor Advisory
- http://secunia.com/advisories/46043Vendor Advisory
- http://secunia.com/advisories/46793Vendor Advisory
- http://secunia.com/advisories/48058Vendor Advisory
- http://secunia.com/advisories/48434Vendor Advisory
FAQ
What is CVE-2011-2915?
CVE-2011-2915 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Off-by-one error in the CSoundFile::ReadAMS2 function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arb...
How severe is CVE-2011-2915?
CVE-2011-2915 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2915?
Check the references section above for vendor advisories and patch information. Affected products include: Konstanty Bialkowski Libmodplug.