libmodplug 'load_abc.cpp' Remote Stack Based Buffer Overflow Vulnerability
BID:47624
Info
libmodplug 'load_abc.cpp' Remote Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 47624 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-1761 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2011 12:00AM |
| Updated: | Apr 13 2015 09:38PM |
| Credit: | epiphant |
| Vulnerable: |
VideoLAN VLC media player 1.1.9 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 11.04 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.10 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 LTS Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 S.u.S.E. openSUSE 11.4 S.u.S.E. openSUSE 11.3 libmodplug libmodplug 0.8.8 2 libmodplug libmodplug 0.8.8 1 libmodplug libmodplug 0.8.7 libmodplug libmodplug 0.8.6 libmodplug libmodplug 0.8.4 libmodplug libmodplug 0.8 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
libmodplug 'load_abc.cpp' Remote Stack Based Buffer Overflow Vulnerability
The libmodplug library is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running an application that uses the affected library. Failed exploit attempts will result in a denial-of-service condition.
libmodplug 0.8.8.2 is vulnerable; other versions may also be affected. Note that the library is used in multiple projects; other applications may also be vulnerable.
The libmodplug library is prone to a remote stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running an application that uses the affected library. Failed exploit attempts will result in a denial-of-service condition.
libmodplug 0.8.8.2 is vulnerable; other versions may also be affected. Note that the library is used in multiple projects; other applications may also be vulnerable.
Solution / Fix
libmodplug 'load_abc.cpp' Remote Stack Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
libmodplug 'load_abc.cpp' Remote Stack Based Buffer Overflow Vulnerability
References:
References:
- libmodplug Homepage (libmodplug)