CVE-2013-4233

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-4233 at MITRE

Description

Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC file, which triggers a heap-based buffer overflow.

NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)

SUSE information

SUSE Bugzilla entry: 834483

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 12.3
  • libmodplug >= 0.8.8.4-9.4.1
  • libmodplug-debugsource >= 0.8.8.4-9.4.1
  • libmodplug-devel >= 0.8.8.4-9.4.1
  • libmodplug1 >= 0.8.8.4-9.4.1
  • libmodplug1-32bit >= 0.8.8.4-9.4.1
  • libmodplug1-debuginfo >= 0.8.8.4-9.4.1
  • libmodplug1-debuginfo-32bit >= 0.8.8.4-9.4.1
Patchnames:
openSUSE-2013-820
openSUSE Evergreen 11.4
  • libmodplug >= 0.8.8.4-2.14.1
  • libmodplug-debugsource >= 0.8.8.4-2.14.1
  • libmodplug-devel >= 0.8.8.4-2.14.1
  • libmodplug0 >= 0.8.8.4-2.14.1
  • libmodplug0-32bit >= 0.8.8.4-2.14.1
  • libmodplug0-debuginfo >= 0.8.8.4-2.14.1
  • libmodplug0-debuginfo-32bit >= 0.8.8.4-2.14.1
  • libmodplug0-debuginfo-x86 >= 0.8.8.4-2.14.1
  • libmodplug0-x86 >= 0.8.8.4-2.14.1
Patchnames:
2013-156