9.3
CVSSv2

CVE-2009-3996

Published: 18/12/2009 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp prior to 5.57, and libmikmod 3.1.12, might allow remote malicious users to execute arbitrary code via an Ultratracker file.

Vulnerable Product Search on Vulmon Subscribe to Product

nullsoft winamp 5.551

nullsoft winamp 5.531

nullsoft winamp 5.51

nullsoft winamp 5.55

nullsoft winamp 5.07

nullsoft winamp 5.08c

nullsoft winamp 5.0.2

nullsoft winamp 5.01

nullsoft winamp 2.80

nullsoft winamp 2.73

nullsoft winamp 2.74

nullsoft winamp 2.60

nullsoft winamp 2.6x

nullsoft winamp 2.0

nullsoft winamp 2.64

nullsoft winamp 2.70

nullsoft winamp 2.9

nullsoft winamp 5.1

nullsoft winamp 5.08

nullsoft winamp 5.091

nullsoft winamp 5.21

nullsoft winamp 5.24

nullsoft winamp 5.52

nullsoft winamp 5.54

nullsoft winamp 5.04

nullsoft winamp 5.09

nullsoft winamp 3.1

nullsoft winamp 5.03a

nullsoft winamp 2.7x

nullsoft winamp 2.95

nullsoft winamp 2.77

nullsoft winamp 2.78

nullsoft winamp 2.61

nullsoft winamp 2.65

nullsoft winamp 2.10

nullsoft winamp 2.50

nullsoft winamp 1.90

nullsoft winamp 0.20a

nullsoft winamp 5.111

nullsoft winamp 5.112

nullsoft winamp 5.11

nullsoft winamp 5.2

nullsoft winamp 5.3

nullsoft winamp 5.33

raphael assenat libmikmod 3.1.12

nullsoft winamp 5.541

nullsoft winamp 5.5

nullsoft winamp 5.08e

nullsoft winamp 5.08d

nullsoft winamp 5.03

nullsoft winamp 5.02

nullsoft winamp 3.0

nullsoft winamp 2.90

nullsoft winamp 2.91

nullsoft winamp 2.75

nullsoft winamp 2.76

nullsoft winamp 2.4

nullsoft winamp 2.62

nullsoft winamp 0.92

nullsoft winamp 2.92

nullsoft winamp 5.34

nullsoft winamp 5.35

nullsoft winamp 5.13

nullsoft winamp 5.093

nullsoft winamp 5.32

nullsoft winamp 5.22

nullsoft winamp 5.552

nullsoft winamp 5.53

nullsoft winamp 5.06

nullsoft winamp 5.05

nullsoft winamp 5.0.1

nullsoft winamp 5.0

nullsoft winamp 2.81

nullsoft winamp 2.79

nullsoft winamp 2.71

nullsoft winamp 2.72

nullsoft winamp 2.5e

nullsoft winamp 2.24

nullsoft winamp 1.006

nullsoft winamp 2.6

nullsoft winamp 5.36

nullsoft winamp 5.12

nullsoft winamp 5.094

nullsoft winamp 5.31

nullsoft winamp 5.23

nullsoft winamp

Vendor Advisories

Synopsis Moderate: mikmod security update Type/Severity Security Advisory: Moderate Topic Updated mikmod packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 3, 4, and 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vul ...
Debian Bug report logs - #575742 CVE-2009-3995 CVE-2009-3996: Multiple heap-based buffer overflows Package: libmikmod; Maintainer for libmikmod is Stephen Kitt <skitt@debianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Sun, 28 Mar 2010 21:12:01 UTC Severity: serious Tags: patch, security Fixed in ...
It was discovered that libMikMod incorrectly handled songs with different channel counts If a user were tricked into opening a crafted song file, an attacker could cause a denial of service (CVE-2007-6720) ...
Dyon Balding discovered buffer overflows in the MikMod sound library, which could lead to the execution of arbitrary code if a user is tricked into opening malformed Impulse Tracker or Ultratracker sound files For the stable distribution (lenny), these problems have been fixed in version 3111-6+lenny1 For the unstable distribution (sid), these ...