CVE-2010-2546

Multiple heap-based buffer overflows in loaders/load_it.c in libmikmod, possibly 3.1.12, might allow remote attackers to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file, related to panpts, pitpts, and IT_ProcessEnvelope.  NOTE: some of these details are obtained from third party information.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3995.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
raphael_assenatlibmikmod
3.1.12
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libmikmod
bullseye
3.3.11.1-6
fixed
bookworm
3.3.11.1-7
fixed
sid
3.3.11.1-8
fixed
trixie
3.3.11.1-8
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libmikmod
lucid
Fixed 3.1.11-6.1ubuntu0.1
released
karmic
Fixed 3.1.11-6ubuntu4.1
released
jaunty
Fixed 3.1.11-6ubuntu3.9.04.1
released
hardy
Fixed 3.1.11-6ubuntu3.8.04.1
released
dapper
ignored