Back to Database
Status published
Medium
CVE-2011-1574
Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in...
Vulnerability Description
Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers to execute arbitrary code via a crafted S3M file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-1574
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.ubuntu.com/usn/USN-1148-1/
- http://openwall.com/lists/oss-security/2011/04/11/13
- http://www.gentoo.org/security/en/glsa/glsa-201203-16.xml
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622091
- https://www.sec-consult.com/files/20110407-0_libmodplug_stackoverflow.txt
- http://secunia.com/advisories/44870
- http://openwall.com/lists/oss-security/2011/04/11/6
- https://bugzilla.redhat.com/show_bug.cgi?id=695420
- http://securitytracker.com/id?1025480
- http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms%3Ba=commit%3Bh=aecef259828a89bb00c2e6f78e89de7363b2237b
- http://secunia.com/advisories/48434
- http://www.debian.org/security/2011/dsa-2226
- http://securityreason.com/securityalert/8243
- https://rhn.redhat.com/errata/RHSA-2011-0477.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:085
More from konstanty bialkowski
View All →CVE-2013-4234
Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2)...
Medium
6.8
CVE-2013-4233
Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug...
Medium
6.8
CVE-2011-2915
Off-by-one error in the CSoundFile::ReadAMS2 function in src/load_ams.cpp in libmodplug...
Medium
6.8
CVE-2011-2914
Off-by-one error in the CSoundFile::ReadDSM function in src/load_dms.cpp in libmodplug...
Medium
6.8
CVE-2011-2913
Off-by-one error in the CSoundFile::ReadAMS function in src/load_ams.cpp in libmodplug...
Medium
6.8
Affected Vendor
konstanty bialkowski
View all reports →Affected Software
libmodplug
Vulnerable Versions:
0, 0.8, 0.8.4, 0.8.5, 0.8.6, 0.8.7, 0.8.8
Timeline
Official Publish:
May 9th, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.