CVE-2011-2913: Medium severity suse libmodplug1 vulnerability
Off-by-one error in the CSoundFile::ReadAMS function in src/loadams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (stack memory corruption) and possibly execute arbitrary code via a crafted AMS file with a large number of samples.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2913?
CVE-2011-2913 has a high severity due to the potential for stack memory corruption and arbitrary code execution.
How do I fix CVE-2011-2913?
To fix CVE-2011-2913, upgrade libmodplug to version 0.8.8.4 or later.
What software versions are affected by CVE-2011-2913?
CVE-2011-2913 affects libmodplug versions up to 0.8.8.3, including versions 0.8.4, 0.8.5, 0.8.6, 0.8.7, and 0.8.8.1 to 0.8.8.3.
What type of vulnerability is CVE-2011-2913?
CVE-2011-2913 is an off-by-one error vulnerability in the CSoundFile::ReadAMS function.
What can attackers achieve by exploiting CVE-2011-2913?
By exploiting CVE-2011-2913, attackers can cause denial of service through stack memory corruption and potentially execute arbitrary code.