MEDIUM
file: heap-based buffer overflow in cdf_read_sat()
Published May 4, 2009
6.8
MEDIUMCVSS 2.0
EPSS 3.65%
Description
Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.
Affected products
No data.
- 5.00
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (13)
- ftp://ftp.astron.com/pub/file/file-5.01.tar.gz x_refsource_CONFIRM
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=515603 x_refsource_MISC
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=525820 x_refsource_MISC
- http://mx.gw.com/pipermail/file/2009/000379.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/34881 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:129 vendor-advisoryx_refsource_MANDRIVA
- http://www.osvdb.org/54100 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/34745 vdb-entryx_refsource_BIDExploit
- https://access.redhat.com/security/cve/CVE-2009-1515 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=497913 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1512 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-1515
- https://www.cve.org/CVERecord?id=CVE-2009-1515
| Link | Providers | Tags |
|---|---|---|
| ftp://ftp.astron.com/pub/file/file-5.01.tar.gz | x_refsource_CONFIRM | |
| http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=515603 | x_refsource_MISC | |
| http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=525820 | x_refsource_MISC | |
| http://mx.gw.com/pipermail/file/2009/000379.html | mailing-listx_refsource_MLIST | |
| http://secunia.com/advisories/34881 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2009:129 | vendor-advisoryx_refsource_MANDRIVA | |
| http://www.osvdb.org/54100 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/bid/34745 | vdb-entryx_refsource_BIDExploit | |
| https://access.redhat.com/security/cve/CVE-2009-1515 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=497913 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1512 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-1515 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-1515 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 4, 2009
Updated Aug 7, 2024
Reserved May 4, 2009
Link CVE-2009-1515
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-1512 Assigner mitre
Published May 4, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-1512