USN-1255-1: libmodplug vulnerabilities
9 November 2011
libmodplug could be made to crash or run programs as your login if it opened a specially crafted file.
Releases
Packages
- libmodplug - Library for mod music based on ModPlug
Details
Hossein Lotfi discovered that libmodplug did not correctly handle certain
malformed media files. If a user or automated system were tricked into
opening a crafted media file, an attacker could cause a denial of service
or possibly execute arbitrary code with privileges of the user invoking the
program. (CVE-2011-2911, CVE-2011-2912, CVE-2011-2913)
It was discovered that libmodplug did not correctly handle certain
malformed media files. If a user or automated system were tricked into
opening a crafted media file, an attacker could cause a denial of service
or possibly execute arbitrary code with privileges of the user invoking the
program. (CVE-2011-2914, CVE-2011-2915)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 11.10
Ubuntu 11.04
Ubuntu 10.10
Ubuntu 10.04
In general, a standard system update will make all the necessary changes.