CVE-2011-2911
CVE-2011-2911
Integer overflow in the CSoundFile::ReadWav function in src/load_wav.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted WAV file, which triggers a heap-based buffer overflow.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://jira.atheme.org/browse/AUDPLUG-394http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063786.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-September/066044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-08/msg00019.htmlhttp://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms%3Ba=commitdiff%3Bh=2d4c56de314ab13e4437bd8b609f0b751066eee8http://rhn.redhat.com/errata/RHSA-2011-1264.htmlhttp://secunia.com/advisories/45131http://secunia.com/advisories/45658http://secunia.com/advisories/45742http://secunia.com/advisories/45901http://secunia.com/advisories/46032http://secunia.com/advisories/46043