Back to Database
Status published
Medium
CVE-2013-1980
Buffer overflow in the get_dsmp function in loaders/masi_load.c in libxmp...
Vulnerability Description
Buffer overflow in the get_dsmp function in loaders/masi_load.c in libxmp before 4.1.0 allows remote attackers to execute arbitrary code via a crafted MASI file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-1980
Credits & Attribution
No credits recorded in the NVD database.
References
- http://sourceforge.net/projects/xmp/files/libxmp/4.1.0/Changelog/view
- http://www.openwall.com/lists/oss-security/2013/04/22/12
- https://bugzilla.redhat.com/show_bug.cgi?id=954658
- http://sourceforge.net/p/xmp/libxmp/ci/a015fdfb478a60172fd225632a11bbd02870fc40
- https://build.opensuse.org/request/show/174356
- http://secunia.com/advisories/53114
- http://www.securityfocus.com/bid/59355
Affected Vendor
extended module player project
View all reports →Affected Software
extended module player
Vulnerable Versions:
0, 4.0.0, 4.0.1, 4.0.2, 4.0.3
Timeline
Official Publish:
February 11th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.