9.3
CVSSv2

CVE-2009-1791

Published: 26/05/2009 Updated: 17/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 up to and including 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mega-nerd libsndfile 1.0.16

mega-nerd libsndfile 1.0.15

nullsoft winamp 5.552

mega-nerd libsndfile 1.0.19

nullsoft winamp 5.51

nullsoft winamp 5.52

mega-nerd libsndfile 1.0.18

mega-nerd libsndfile 1.0.17

nullsoft winamp 5.5

nullsoft winamp 5.55

nullsoft winamp 5.54

nullsoft winamp 5.541

Vendor Advisories

Debian Bug report logs - #528650 libsndfile1: Potential heap overflow in all versions <= 1019 Package: libsndfile1; Maintainer for libsndfile1 is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for libsndfile1 is src:libsndfile (PTS, buildd, popcon) Reported by: Erik de Castro Lopo <erikd@m ...
Tobias Klein discovered a heap-based buffer overflow in libsndfile If a user or automated system processed a crafted VOC file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2009-1788) ...
Two vulnerabilities have been found in libsndfile, a library to read and write sampled audio data The Common Vulnerabilities and Exposures project identified the following problems: CVE-2009-1788 Tobias Klein discovered that the VOC parsing routines suffer of a heap-based buffer overflow which can be triggered by an attacker via a crafted VOC hea ...