HIGH
libmikmod: arbitrary code execution via crafted Impulse Tracker or Ultratracker files
Published Dec 18, 2009
9.3
HIGHCVSS 2.0
EPSS 6.72%
Description
Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file. NOTE: some of these details are obtained from third party information.
Affected products
No data.
OR
- ≤ 5.56
- 0.20a
- 0.92
- 1.006
- 1.90
- 2.0
- 2.4
- 2.5e
- 2.6
- 2.6x
- 2.7x
- 2.9
- 2.10
- 2.24
- 2.50
- 2.60
- 2.60
- 2.60
- 2.61
- 2.61
- 2.62
- 2.62
- 2.64
- 2.64
- 2.65
- 2.70
- 2.70
- 2.71
- 2.72
- 2.73
- 2.73
- 2.74
- 2.75
- 2.76
- 2.77
- 2.78
- 2.79
- 2.80
- 2.81
- 2.90
- 2.91
- 2.92
- 2.95
- 3.0
- 3.1
- 5.0
- 5.0.1
- 5.0.2
- 5.01
- 5.1
- 5.1
- 5.02
- 5.2
- 5.3
- 5.03
- 5.03a
- 5.04
- 5.05
- 5.5
- 5.06
- 5.07
- 5.08
- 5.08
- 5.08
- 5.08
- 5.08c
- 5.08d
- 5.08e
- 5.09
- 5.11
- 5.12
- 5.13
- 5.21
- 5.22
- 5.23
- 5.24
- 5.31
- 5.32
- 5.33
- 5.34
- 5.35
- 5.36
- 5.51
- 5.52
- 5.53
- 5.54
- 5.55
- 5.091
- 5.093
- 5.094
- 5.111
- 5.112
- 5.531
- 5.541
- 5.551
- 5.552
- 3.1.12
No data.
Red Hat Enterprise Linux 3
mikmod-0:3.1.6-23.el3
Fixed · RHSA-2010:0720
Red Hat Enterprise Linux 4
mikmod-0:3.1.6-33.el4_8.1
Fixed · RHSA-2010:0720
Red Hat Enterprise Linux 5
mikmod-0:3.1.6-39.el5_5.1
Fixed · RHSA-2010:0720
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | mikmod-0:3.1.6-23.el3 | Fixed | RHSA-2010:0720 |
| Red Hat Enterprise Linux 4 | mikmod-0:3.1.6-33.el4_8.1 | Fixed | RHSA-2010:0720 |
| Red Hat Enterprise Linux 5 | mikmod-0:3.1.6-39.el5_5.1 | Fixed | RHSA-2010:0720 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (18)
- http://forums.winamp.com/showthread.php?threadid=315355 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/37495 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/40799 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/secunia_research/2009-52/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2009-53/ x_refsource_MISCVendor Advisory
- http://secunia.com/secunia_research/2009-55/ x_refsource_MISCVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:151 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/archive/1/508526/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/508527/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/37374 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/3575 vdb-entryx_refsource_VUPENPatchVendor Advisory
- http://www.vupen.com/english/advisories/2010/1107 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/1957 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-3995 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=614643 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2009-3995
- https://www.cve.org/CVERecord?id=CVE-2009-3995
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner flexera
Published Dec 18, 2009
Updated Aug 7, 2024
Reserved Nov 19, 2009
Link CVE-2009-3995
CISA Vulnrichment
Updated n/a