CVE-2007-6720

NameCVE-2007-6720
SourceCVE (at NVD; RH)
Descriptionlibmikmod 3.1.9 through 3.2.0, as used by MikMod, SDL-mixer, and possibly other products, relies on the channel count of the last loaded song, rather than the currently playing song, for certain playback calculations, which allows user-assisted attackers to cause a denial of service (application crash) by loading multiple songs (aka MOD files) with different numbers of channels.
NVD severitymedium (attack range: remote, user-initiated)
Debian Bugs422021, 461519
Debian/oldstablepackage libmikmod is vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libmikmod (PTS)lenny, lenny (security)3.1.11-6.0.1+lenny1vulnerable
squeeze3.1.11-6.3fixed
wheezy, sid3.1.12-2fixed
sdl-mixer1.2 (PTS)lenny1.2.8-4fixed
squeeze1.2.8-6.3fixed
wheezy, sid1.2.12-1fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libmikmodsource(unstable)3.1.11-6.1low461519
sdl-mixer1.2source(unstable)1.2.8-1low422021

Notes

[etch] - libmikmod <no-dsa> (Minor issue)
[lenny] - libmikmod <no-dsa> (Minor issue)
[etch] - sdl-mixer1.2 <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint