Vulnerability Scanning Solutions, LLC.
Our Process
What We Scan For
Sample Report
Client List
Contact Us
What We Scan For
Family: Mandrake Local Security Checks --> Category: infos

MDKSA-2007:001: libmodplug Vulnerability Scan

Vulnerability Scan Summary
Check for the version of the libmodplug package

Detailed Explanation for this Vulnerability Test

The remote host is missing the patch for the advisory MDKSA-2007:001 (libmodplug).

Multiple buffer overflows in MODPlug Tracker (OpenMPT) and
earlier and libmodplug 0.8 and earlier allow user-assisted remote
attackers to execute arbitrary code via (1) long strings in ITP files
used by the CSoundFile::ReadITProject function in soundlib/Load_it.cpp
and (2) crafted modules used by the CSoundFile::ReadSample function in
soundlib/Sndfile.cpp, as demonstrated by crafted AMF files.
Updated packages are patched to address this issue.

Solution :
Threat Level: High

Click HERE for more information and discussions on this network vulnerability scan.


P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.