CVE-2011-2914: Medium severity suse libmodplug1 vulnerability
Published Jun 7, 2012
·Updated
Off-by-one error in the CSoundFile::ReadDSM function in src/loaddms.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted DSM file with a large number of samples.
Affected Software
9 affected components
Konstanty Bialkowski Libmodplug=0.8.5
Konstanty Bialkowski Libmodplug=0.8.7
Konstanty Bialkowski Libmodplug<=0.8.8.3
Konstanty Bialkowski Libmodplug=0.8.4
Konstanty Bialkowski Libmodplug=0.8.8.1
Konstanty Bialkowski Libmodplug=0.8.8.2
Konstanty Bialkowski Libmodplug=0.8.8
Konstanty Bialkowski Libmodplug=0.8
Konstanty Bialkowski Libmodplug=0.8.6
Event History
Jun 7, 2012
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2914?
CVE-2011-2914 is considered to have a high severity due to the potential for denial of service and arbitrary code execution.
2
How do I fix CVE-2011-2914?
To fix CVE-2011-2914, upgrade libmodplug to version 0.8.8.4 or later.
3
Which versions of software are affected by CVE-2011-2914?
CVE-2011-2914 affects libmodplug versions 0.8.5 through 0.8.8.3.
4
What type of vulnerability is CVE-2011-2914?
CVE-2011-2914 is an off-by-one memory corruption vulnerability.
5
Can CVE-2011-2914 lead to remote attacks?
Yes, CVE-2011-2914 can allow remote attackers to execute arbitrary code through crafted DSM files.