HIGH
libsndfile VOC file heap based buffer overflow
Published May 26, 2009
9.3
HIGHCVSS 2.0
EPSS 8.23%
Description
Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.
Affected products
No data.
OR
- 1.0.15
- 1.0.16
- 1.0.17
- 1.0.18
- 1.0.19
- 5.5
- 5.51
- 5.52
- 5.54
- 5.55
- 5.541
- 5.552
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (20)
- http://secunia.com/advisories/35076 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35126 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35247 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35443 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200905-09.xml vendor-advisoryx_refsource_GENTOO
- http://trapkit.de/advisories/TKADV2009-006.txt x_refsource_MISCExploit
- http://www.debian.org/security/2009/dsa-1814 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:132 vendor-advisoryx_refsource_MANDRIVA
- http://www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/ x_refsource_CONFIRMPatchVendor Advisory
- http://www.mega-nerd.com/libsndfile/ x_refsource_CONFIRMPatch
- http://www.securityfocus.com/bid/34978 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2009/1324 vdb-entryx_refsource_VUPENPatchVendor Advisory
- http://www.vupen.com/english/advisories/2009/1348 vdb-entryx_refsource_VUPENPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-1788 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=502657 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1783 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50541 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50827 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-1788
- https://www.cve.org/CVERecord?id=CVE-2009-1788
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 26, 2009
Updated Aug 7, 2024
Reserved May 26, 2009
Link CVE-2009-1788
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-1783 Assigner mitre
Published May 26, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-1783