LWN.net Logo

xmp: buffer overflows

Package(s):xmp CVE #(s):CVE-2007-6731 CVE-2007-6732
Created:September 24, 2009 Updated:September 30, 2009
Description: From the National Vulnerability Database entrys:

CVE-2007-6731: "Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in test_oxm and decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow."

CVE-2007-6732: "Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the pofs and plen arrays."

Alerts:
Fedora FEDORA-2009-9675 2009-09-16
Fedora FEDORA-2009-9671 2009-09-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds