|
|
| |
|
| |
libmodplug: two code execution vulnerabilities
| Package(s): | libmodplug |
CVE #(s): | CVE-2013-4233
CVE-2013-4234
|
| Created: | September 5, 2013 |
Updated: | September 16, 2013 |
| Description: |
From the Red Hat bugzilla entry:
It was reported [1],[2] that libmodplug suffers from two flaws when parsing ABC files:
1) An error within the "abc_MIDI_drum()" function (src/load_abc.cpp) can be exploited to cause a buffer overflow via a specially crafted ABC file.
2) An integer overflow within the "abc_set_parts()" function (src/load_abc.cpp) can be exploited to corrupt heap memory via a specially crafted ABC file.
Successful exploitation of the vulnerabilities may allow execution of arbitrary code.
|
| Alerts: |
|
( Log in to post comments)
|
|
|