Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier, as used in GStreamer and possibly other products, allow user-assisted remote attackers to execute arbitrary code via (1) long strings in ITP files used by the CSoundFile::ReadITProject function in soundlib/Load_it.cpp and (2) crafted modules used by the CSoundFile::ReadSample function in soundlib/Sndfile.cpp, as demonstrated by crafted AMF files.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gstreamer-plugins-develUpgrade gstreamer-plugins | Dec 1, 2016 | Aug 16, 2006 |
| Debian | — | Upgrade libmodplug | Jul 30, 2024 | Aug 17, 2006 |
| Gentoo Linux | — | Upgrade media-libs/libmodplug. | Oct 30, 2017 | Aug 16, 2006 |
| Ubuntu | — | Upgrade libmodplug0c2 | Nov 8, 2024 | Aug 17, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub