Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based buffer overflow, as exploited in the wild in August 2008.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libmodplug | Jul 30, 2024 | Apr 27, 2009 |
| Gentoo Linux | — | Upgrade media-libs/gst-plugins-bad.Upgrade media-libs/libmodplug. | Oct 30, 2017 | Apr 27, 2009 |
| Suse | — | Upgrade gstreamer010-plugins-badUpgrade gstreamer-0_10-plugins-badUpgrade gstreamer010-plugins-bad-docUpgrade gstreamer-0_10-plugins-bad-docUpgrade libgstapp-0_10-0Upgrade gstreamer-0_10-plugins-bad-langUpgrade gstreamer010-plugins-bad-develUpgrade gstreamer-0_10-plugins-bad-devel | Feb 17, 2015 | Apr 27, 2009 |
| Ubuntu | — | Upgrade libmodplug0c2 | Nov 8, 2024 | Apr 27, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub