LWN.net Logo

xmp: code execution

Package(s):xmp CVE #(s):CVE-2013-1980
Created:May 31, 2013 Updated:June 5, 2013
Description:

From the Red Hat bug report:

A heap-based buffer overflow flaw was found in the way xmp, the extended module player, a modplayer for Unix-like systems that plays over 90 mainstream and obscure module formats, loaded certain Music And Sound Interface (MASI) files. A remote attacker could provide a specially-crafted MASI media file that, when opened, would lead to xmp binary crash or, potentially, arbitrary code execution with the privileges of the user running the xmp executable.

Alerts:
Fedora FEDORA-2013-7144 2013-05-31
Fedora FEDORA-2013-7135 2013-05-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds