| From: |
| Meltem Parmaksız <meltem@pardus.org.tr> |
| To: |
| pardus-security@pardus.org.tr |
| Subject: |
| [Pardus-security] [PLSA 2011-75] Libmodplug: Stack Overflow |
| Date: |
| Tue, 3 May 2011 14:15:26 +0300 |
| Message-ID: |
| <201105031415.26593.meltem@pardus.org.tr> |
| Archive-link: |
| Article, Thread
|
------------------------------------------------------------------------
Pardus Linux Security Advisory 2011-75 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2011-05-03
Type: Local
------------------------------------------------------------------------
Summary
=======
A vulnerability has been fixed in libmodplug, which allows attackers to
execute arbitrary code.
Description
===========
CVE-2011-1574:
Libmodplug library is prone to a stack based buffer overflow
vulnerability due to insufficient validation of user supplied data. An
attacker is able to execute arbitrary code in the context of the user
when opening malicious S3M media files.
Affected packages:
Pardus 2009:
libmodplug, all before 0.8.7-6-6
Pardus 2011:
libmodplug, all before 0.8.8.2-8-p11
libmodplug-devel, all before 0.8.8.2-8-p11
Resolution
==========
There are update(s) for libmodplug, libmodplug-devel. You can update
them via Package Manager or with a single command from console:
Pardus 2009:
pisi up libmodplug
Pardus 2011:
pisi up libmodplug libmodplug-devel
References
==========
* http://bugs.pardus.org.tr/show_bug.cgi?id=17755
------------------------------------------------------------------------
_______________________________________________
Pardus-Security mailing list
Pardus-Security@pardus.org.tr
http://liste.pardus.org.tr/mailman/listinfo/pardus-security
(
Log in to post comments)