CVE-2011-2915: Medium severity suse libmodplug1 vulnerability
Off-by-one error in the CSoundFile::ReadAMS2 function in src/loadams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted AMS file with a large number of instruments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2915?
CVE-2011-2915 has a severity rating that allows for potential denial of service and arbitrary code execution risks.
How do I fix CVE-2011-2915?
To fix CVE-2011-2915, upgrade to libmodplug version 0.8.8.4 or later.
What causes the vulnerability in CVE-2011-2915?
CVE-2011-2915 is caused by an off-by-one error in the CSoundFile::ReadAMS2 function.
Which versions of libmodplug are affected by CVE-2011-2915?
Versions of libmodplug prior to 0.8.8.4, including 0.8.5, 0.8.6, 0.8.7, and up to 0.8.8.3, are affected by CVE-2011-2915.
Can exploitation of CVE-2011-2915 lead to data loss?
Yes, exploitation of CVE-2011-2915 can result in memory corruption which may lead to data loss.