ModPlug: User-assisted execution of arbitrary code Multiple vulnerabilities in ModPlug could result in execution of arbitrary code or Denial of Service. libmodplug March 16, 2012 March 16, 2012: 2 362503 379557 remote 0.8.8.4 0.8.8.4

ModPlug is a library for playing MOD-like music.

Multiple vulnerabilities have been found in ModPlug:

A remote attacker could entice a user to open a specially crafted media file, possibly resulting in execution of arbitrary code, or a Denial of Service condition.

There is no known workaround at this time.

All ModPlug users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/libmodplug-0.8.8.4"

NOTE: This is a legacy GLSA. Updates for all affected architectures are available since August 27, 2011. It is likely that your system is already no longer affected by this issue.

CVE-2011-1574 CVE-2011-2911 CVE-2011-2912 CVE-2011-2913 CVE-2011-2914 CVE-2011-2915 underling ackle