Multiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ABC file. NOTE: some of these details are obtained from third party information.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libmodplug | Jul 30, 2024 | Jun 7, 2012 |
| Suse | — | Upgrade libmodplug1Upgrade libmodplug-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libmodplug1Upgrade libmodplug0c2 | Nov 8, 2024 | Jun 7, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub