Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
libmodplug could be made to run programs as your login if it opened a
specially crafted file.
Software Description:
- libmodplug: Library for mod music based on ModPlug
Details:
It was discovered that libmodplug did not correctly handle certain
malformed S3M media files. If a user or automated system were tricked into
opening a crafted S3M file, an attacker could cause a denial of service or
possibly execute arbitrary code with privileges of the user invoking the
program. (CVE-2011-1574)
It was discovered that libmodplug did not correctly handle certain
malformed ABC media files. If a user or automated system were tricked into
opening a crafted ABC file, an attacker could cause a denial of service or
possibly execute arbitrary code with privileges of the user invoking the
program. (CVE-2011-1761)
The default compiler options for affected releases should reduce the
vulnerability to a denial of service.
The problem can be corrected by updating your system to the following package versions: Ubuntu 11.04: libmodplug1 1:0.8.8.1-2ubuntu0.2 Ubuntu 10.10: libmodplug1 1:0.8.8.1-1ubuntu1.2 Ubuntu 10.04 LTS: libmodplug0c2 1:0.8.7-1ubuntu0.2 In general, a standard system update will make all the necessary changes.
CVE-2011-1574, CVE-2011-1761
Get the latest Linux and open source security news straight to your inbox.