Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200612-04] ModPlug: Multiple buffer overflows


Vulnerability Assessment Details

[GLSA-200612-04] ModPlug: Multiple buffer overflows

Vulnerability Assessment Summary
ModPlug: Multiple buffer overflows

Detailed Explanation for this Vulnerability Assessment
The remote host is affected by the vulnerability described in GLSA-200612-04
(ModPlug: Multiple buffer overflows)


Luigi Auriemma has reported various boundary errors in load_it.cpp and
a boundary error in the "CSoundFile::ReadSample()" function in
sndfile.cpp.

Impact

A remote attacker can entice a user to read crafted modules or ITP
files, which may trigger a buffer overflow resulting in the execution
of arbitrary code with the rights of the user running the
application.

Workaround

There is no known workaround at this time.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4192


Solution:
All ModPlug users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/libmodplug-0.8-r1"


Network Security Threat Level: Medium


Networks Security ID:

Vulnerability Assessment Copyright: (C) 2006 Michel Arboi

Cables, Connectors


Vintage Disk Bank 5.25

Vintage Disk Bank 5.25" Floppy Disk Storage Box Case Holder w/ Dividers

$29.95



Vintage Addison-Wesley Autodesk Collection PC CD Autocad R12 12 AutoVision etc picture

Vintage Addison-Wesley Autodesk Collection PC CD Autocad R12 12 AutoVision etc

$145.00



Vintage VTECH Equalizer Laptop Computer 90s Works Great W/ Box picture

Vintage VTECH Equalizer Laptop Computer 90s Works Great W/ Box

$89.99



Vintage Computer Printer Floppy Disc Diskette Labels 19 sheets 2.25 x 2.25

Vintage Computer Printer Floppy Disc Diskette Labels 19 sheets 2.25 x 2.25"

$24.00



Vintage Intel Above Board PS/AT Memory 16bit ISA IBM PC XT PS/2 w/Expansion Card picture

Vintage Intel Above Board PS/AT Memory 16bit ISA IBM PC XT PS/2 w/Expansion Card

$209.95



Vintage IBM 1390120 Model M Keyboard 1984 W/Cable Clicky Buckling Spring PS2  picture

Vintage IBM 1390120 Model M Keyboard 1984 W/Cable Clicky Buckling Spring PS2

$65.50



NMB KEYBOARD RT2258TW NMB PS/2 BEIGE 121944-101 REV A VINTAGE NEW OLD STOCK picture

NMB KEYBOARD RT2258TW NMB PS/2 BEIGE 121944-101 REV A VINTAGE NEW OLD STOCK

$25.99



Vintage Apple MacWorld Magazine Mousepad picture

Vintage Apple MacWorld Magazine Mousepad

$15.00



VINTAGE APPLE POWER MACINTOSH 6500/250 DESKTOP COMPUTER POWERPC BOOTS picture

VINTAGE APPLE POWER MACINTOSH 6500/250 DESKTOP COMPUTER POWERPC BOOTS

$249.50



Vintage Dell Dimension L733R Desktop Computer Pentium 3 III Zip 100  PC picture

Vintage Dell Dimension L733R Desktop Computer Pentium 3 III Zip 100 PC

$249.50



Discussions

No Discussions have been posted on this vulnerability.