|
|
| |
|
| |
libmodplug: integer overflow
| Package(s): | libmodplug |
CVE #(s): | CVE-2009-1438
|
| Created: | April 28, 2009 |
Updated: | December 4, 2009 |
| Description: |
From the CVE entry: Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based buffer overflow. |
| Alerts: |
|
( Log in to post comments)
|
|
|