Buffer overflow - CVE-2013-4234
Published: September 16, 2013 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted ABC.
Affected software
Fedora
libmodplug (Alpine package)
jansson (Alpine package)
libmodplug
How to mitigate CVE-2013-4234
jansson (Alpine package) - update to 2.6-r0
libmodplug - update to 0.8.8.5-1.el6