Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44886
HistoryDec 28, 2023 - 11:41 a.m.

Buffer Overflow

2023-12-2811:41:06
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
buffer overflow
libmikmod
load_ult.c
dos
software

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.199

Percentile

96.3%

libmikmod.so is vulnerable to Buffer Overflow. The vulnerability is due in load_ult.c there is no boundary check for the number of channels numchn, This allows an attacker can craft a file with an abnormally high number of channels cause buffer overflow potentially leads to DOS.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.199

Percentile

96.3%