Jump to content

Advisories MDKSA-2007:001: Update libmodplug packages fix buffer overflow vulnerabilities


paul
 Share

Recommended Posts

Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and

earlier and libmodplug 0.8 and earlier allow user-assisted remote

attackers to execute arbitrary code via (1) long strings in ITP files

used by the CSoundFile::ReadITProject function in soundlib/Load_it.cpp

and (2) crafted modules used by the CSoundFile::ReadSample function in

soundlib/Sndfile.cpp, as demonstrated by crafted AMF files.

 

Updated packages are patched to address this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...