← Vulnerability feed

Vulnerability record · CVE-2011-1574 · published 9 May 2011

CVE-2011-1574: Konstanty bialkowski libmodplug memory buffer overflow vulnerability

KKonstanty Bialkowski · Libmodplug

Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers to execute arbitrary code via a crafted S3M file.

6.8 CVSS 2.0 Medium EPSS 43% · top 1.3% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers to execute arbitrary code via a crafted S3M file.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622091 Patch
http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms%3Ba=commit%3Bh=aecef259828a89bb00c2e6
http://openwall.com/lists/oss-security/2011/04/11/13 ExploitPatch
http://openwall.com/lists/oss-security/2011/04/11/6 ExploitPatch
http://secunia.com/advisories/44870
http://secunia.com/advisories/48434
http://securityreason.com/securityalert/8243
http://securitytracker.com/id?1025480
http://www.debian.org/security/2011/dsa-2226
http://www.gentoo.org/security/en/glsa/glsa-201203-16.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2011:085
https://bugzilla.redhat.com/show_bug.cgi?id=695420 ExploitPatch
https://rhn.redhat.com/errata/RHSA-2011-0477.html
https://www.sec-consult.com/files/20110407-0_libmodplug_stackoverflow.txt Exploit
https://www.ubuntu.com/usn/USN-1148-1/
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622091 Patch
http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms%3Ba=commit%3Bh=aecef259828a89bb00c2e6
http://openwall.com/lists/oss-security/2011/04/11/13 ExploitPatch
http://openwall.com/lists/oss-security/2011/04/11/6 ExploitPatch
http://secunia.com/advisories/44870
http://secunia.com/advisories/48434
http://securityreason.com/securityalert/8243
http://securitytracker.com/id?1025480
http://www.debian.org/security/2011/dsa-2226
http://www.gentoo.org/security/en/glsa/glsa-201203-16.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2011:085
https://bugzilla.redhat.com/show_bug.cgi?id=695420 ExploitPatch
https://rhn.redhat.com/errata/RHSA-2011-0477.html
https://www.sec-consult.com/files/20110407-0_libmodplug_stackoverflow.txt Exploit
https://www.ubuntu.com/usn/USN-1148-1/

Track CVE-2011-1574 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2009-1438Konstanty bialkowski libmodplug vulnerabilityInteger overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other…EPSS 4.7%6.8CVE-2013-4234Konstanty bialkowski libmodplug memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier all…EPSS 4.4%6.8CVE-2013-4233Konstanty bialkowski libmodplug vulnerabilityInteger overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service…EPSS 4.1%6.8CVE-2011-2911Konstanty bialkowski libmodplug vulnerabilityInteger overflow in the CSoundFile::ReadWav function in src/load_wav.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of se…EPSS 4.3%6.8CVE-2011-2912Konstanty bialkowski libmodplug memory buffer overflow vulnerabilityStack-based buffer overflow in the CSoundFile::ReadS3M function in src/load_s3m.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a d…EPSS 4.3%6.8CVE-2011-2913Konstanty bialkowski libmodplug vulnerabilityOff-by-one error in the CSoundFile::ReadAMS function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of se…EPSS 4.6%6.8CVE-2011-2914Konstanty bialkowski libmodplug vulnerabilityOff-by-one error in the CSoundFile::ReadDSM function in src/load_dms.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of se…EPSS 4.6%6.8CVE-2011-2915Konstanty bialkowski libmodplug vulnerabilityOff-by-one error in the CSoundFile::ReadAMS2 function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of s…EPSS 4.2%

Source: NIST National Vulnerability Database (record CVE-2011-1574), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.