CVE-2009-1791
Last modified
CVE-2009-1791 is a vulnerability of currently unknown severity. Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.. EPSS estimates a 6.53% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mega-Nerd | Libsndfile | 1.0.15 |
| Mega-Nerd | Libsndfile | 1.0.16 |
| Mega-Nerd | Libsndfile | 1.0.17 |
| Mega-Nerd | Libsndfile | 1.0.18 |
| Mega-Nerd | Libsndfile | 1.0.19 |
| Nullsoft | Winamp | 5.5 |
| Nullsoft | Winamp | 5.51 |
| Nullsoft | Winamp | 5.52 |
| Nullsoft | Winamp | 5.54 |
| Nullsoft | Winamp | 5.55 |
| Nullsoft | Winamp | 5.541 |
| Nullsoft | Winamp | 5.552 |
References
- http://secunia.com/advisories/35076Vendor Advisory
- http://www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/Patch, Vendor Advisory
- http://www.mega-nerd.com/libsndfile/Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1324Patch, Vendor Advisory
- http://secunia.com/advisories/35076Vendor Advisory
- http://www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/Patch, Vendor Advisory
- http://www.mega-nerd.com/libsndfile/Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1324Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1791?
How severe is CVE-2009-1791?
How do I fix CVE-2009-1791?
Are you affected by CVE-2009-1791?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
