Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-0490Out-of-bounds Write in Audacity

Severity
9.3CRITICALNVD
EPSS
58.1%
top 1.81%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedFeb 10
Latest updateMay 2

Description

Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

Debianaudacityteam/audacity< 1.3.6-1+3

🔴Vulnerability Details

3
GHSA
GHSA-8f8x-6454-8222: Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse2022-05-02
OSV
CVE-2009-0490: Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse2009-02-10
CVEList
CVE-2009-0490: Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse2009-02-10

💥Exploits & PoCs

3
Exploit-DB
Audacity 1.2.6 - '.gro' Local Buffer Overflow2009-12-05
Exploit-DB
Audacity 1.2 - '.gro' Universal Buffer Overflow (Egghunter)2009-08-24
Exploit-DB
Audacity 1.2.6 - '.gro' Local Buffer Overflow (PoC)2009-01-01

📋Vendor Advisories

2
Red Hat
audacity: stack-based buffer overflow2009-01-02
Debian
CVE-2009-0490: audacity - Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in...2009

💬Community

4
Bugzilla
CVE-2009-0490 audacity: stack-based buffer overflow [Fdevel]2009-02-10
Bugzilla
CVE-2009-0490 audacity: stack-based buffer overflow2009-02-10
Bugzilla
CVE-2009-0490 audacity: stack-based buffer overflow [F9]2009-02-10
Bugzilla
CVE-2009-0490 audacity: stack-based buffer overflow [F10]2009-02-10
CVE-2009-0490 — Out-of-bounds Write in Audacity | cvebase