9.3
CVSSv2

CVE-2009-3995

Published: 18/12/2009 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp prior to 5.57, and libmikmod 3.1.12, might allow remote malicious users to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

nullsoft winamp 5.551

nullsoft winamp 5.531

nullsoft winamp 5.51

nullsoft winamp 5.55

nullsoft winamp 5.08d

nullsoft winamp 5.08c

nullsoft winamp 5.01

nullsoft winamp 2.80

nullsoft winamp 2.91

nullsoft winamp 2.73

nullsoft winamp 2.76

nullsoft winamp 2.60

nullsoft winamp 2.6x

nullsoft winamp 2.0

nullsoft winamp 2.62

nullsoft winamp 2.64

nullsoft winamp 2.92

nullsoft winamp 2.9

nullsoft winamp 5.1

nullsoft winamp 5.08

nullsoft winamp 5.093

nullsoft winamp 5.091

nullsoft winamp 5.21

nullsoft winamp 5.24

nullsoft winamp 5.52

nullsoft winamp 5.54

nullsoft winamp 5.05

nullsoft winamp 5.04

nullsoft winamp 3.1

nullsoft winamp 5.03a

nullsoft winamp 2.7x

nullsoft winamp 2.95

nullsoft winamp 2.72

nullsoft winamp 2.77

nullsoft winamp 2.61

nullsoft winamp 2.65

nullsoft winamp 2.10

nullsoft winamp 1.006

nullsoft winamp 1.90

nullsoft winamp 5.111

nullsoft winamp 5.112

nullsoft winamp 5.12

nullsoft winamp 5.11

nullsoft winamp 5.31

nullsoft winamp 5.3

raphael assenat libmikmod 3.1.12

nullsoft winamp 5.552

nullsoft winamp 5.53

nullsoft winamp 5.07

nullsoft winamp 5.06

nullsoft winamp 5.0.2

nullsoft winamp 5.0.1

nullsoft winamp 5.0

nullsoft winamp 2.81

nullsoft winamp 2.79

nullsoft winamp 2.74

nullsoft winamp 2.71

nullsoft winamp 2.5e

nullsoft winamp 2.24

nullsoft winamp 2.70

nullsoft winamp 2.6

nullsoft winamp 5.36

nullsoft winamp 5.094

nullsoft winamp 5.23

nullsoft winamp

nullsoft winamp 5.541

nullsoft winamp 5.5

nullsoft winamp 5.09

nullsoft winamp 5.08e

nullsoft winamp 5.03

nullsoft winamp 5.02

nullsoft winamp 3.0

nullsoft winamp 2.90

nullsoft winamp 2.78

nullsoft winamp 2.75

nullsoft winamp 2.50

nullsoft winamp 2.4

nullsoft winamp 0.20a

nullsoft winamp 0.92

nullsoft winamp 5.34

nullsoft winamp 5.35

nullsoft winamp 5.2

nullsoft winamp 5.13

nullsoft winamp 5.33

nullsoft winamp 5.32

nullsoft winamp 5.22

Vendor Advisories

Synopsis Moderate: mikmod security update Type/Severity Security Advisory: Moderate Topic Updated mikmod packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 3, 4, and 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vul ...
Debian Bug report logs - #575742 CVE-2009-3995 CVE-2009-3996: Multiple heap-based buffer overflows Package: libmikmod; Maintainer for libmikmod is Stephen Kitt <skitt@debianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Sun, 28 Mar 2010 21:12:01 UTC Severity: serious Tags: patch, security Fixed in ...
It was discovered that libMikMod incorrectly handled songs with different channel counts If a user were tricked into opening a crafted song file, an attacker could cause a denial of service (CVE-2007-6720) ...
Dyon Balding discovered buffer overflows in the MikMod sound library, which could lead to the execution of arbitrary code if a user is tricked into opening malformed Impulse Tracker or Ultratracker sound files For the stable distribution (lenny), these problems have been fixed in version 3111-6+lenny1 For the unstable distribution (sid), these ...