Saturday, October 2, 2010

libMikMod: DoS, code-execution vulnerabilities

Users of libMikMod please be advised of a DoS, code-execution vulnerabilities that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
USN-995-1: [USN-995-1] libMikMod DoS, code-execution vulnerabilities
Details follow:



It was discovered that libMikMod incorrectly handled songs with different

channel counts. If a user were tricked into opening a crafted song file,

an attacker could cause a denial of service. (CVE-2007-6720)



It was discovered that libMikMod incorrectly handled certain malformed XM

files. If a user were tricked into opening a crafted XM file, an attacker

could cause a denial of service. (CVE-2009-0179)
Read more at www.criticalwatch.com
 

No comments:

Post a Comment