RSS   Podatności dla 'Extended module player'   RSS

2009-09-13
 
CVE-2007-6732

CWE-119
 

 
Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays.

 
 
CVE-2007-6731

CWE-94
 

 
Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow.

 


Copyright 2024, cxsecurity.com

 

Back to Top