Libmodplug "CSoundFile: ReadS3M ()" Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
Libmodplug
Description:
--------------------------------------------------------------------------------
Libmodplug is an open-source function library used to play mod music formats.
Libmodplug's "CSoundFile: ReadS3M ()" has a buffer overflow vulnerability. Remote attackers can exploit this vulnerability to control the affected applications.
This vulnerability is caused by a boundary error of "CSoundFile: ReadS3M ()" in src/load_s3m.cpp, which induces users to open a specially crafted S3M file to cause stack buffer overflow.
<* Source: M. Lucinskij
P. Tumenas
Link: http://marc.info /? L = bugtraq & m = 130218718323155 & w = 2
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Libmodplug
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://modplug-xmms.sourceforge.net/