CVE-2007-6732 Information

Description

Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays.

Reference

http://aluigi.altervista.org/adv/xmpbof-adv.txt http://www.securityfocus.com/bid/27047 http://www.vupen.com/english/advisories/2008/0009

Share on: