9.3
CVSSv2

CVE-2009-1791

Published: 26/05/2009 Updated: 17/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 up to and including 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nullsoft winamp 5.552

mega-nerd libsndfile 1.0.18

mega-nerd libsndfile 1.0.19

mega-nerd libsndfile 1.0.15

nullsoft winamp 5.54

nullsoft winamp 5.5

mega-nerd libsndfile 1.0.17

nullsoft winamp 5.55

nullsoft winamp 5.51

nullsoft winamp 5.541

nullsoft winamp 5.52

mega-nerd libsndfile 1.0.16

Vendor Advisories

Tobias Klein discovered a heap-based buffer overflow in libsndfile If a user or automated system processed a crafted VOC file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2009-1788) ...
Debian Bug report logs - #528650 libsndfile1: Potential heap overflow in all versions <= 1019 Package: libsndfile1; Maintainer for libsndfile1 is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for libsndfile1 is src:libsndfile (PTS, buildd, popcon) Reported by: Erik de Castro Lopo <erikd@m ...
Two vulnerabilities have been found in libsndfile, a library to read and write sampled audio data The Common Vulnerabilities and Exposures project identified the following problems: CVE-2009-1788 Tobias Klein discovered that the VOC parsing routines suffer of a heap-based buffer overflow which can be triggered by an attacker via a crafted VOC hea ...