LWN.net Logo

libmikmod: arbitrary code execution

Package(s):libmikmod CVE #(s):CVE-2010-2971
Created:August 16, 2010 Updated:January 20, 2011
Description: From the CVE entry:

loaders/load_it.c in libmikmod, possibly 3.1.12, does not properly account for the larger size of name##env relative to name##tick and name##node, which allows remote attackers to trigger a buffer over-read and possibly have unspecified other impact via a crafted Impulse Tracker file, a related issue to CVE-2010-2546. NOTE: this issue exists because of an incomplete fix for CVE-2009-3995.

Alerts:
MeeGo MeeGo-SA-10:29 2010-10-09
Ubuntu USN-995-1 2010-09-29
Mandriva MDVSA-2010:151 2010-08-16
Gentoo 201203-10 2012-03-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds