CVE-2009-1515
published 2009-05-04CVE-2009-1515: Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.65%
88.4th percentile
Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| christos_zoulas | file | — | — |
| debian | file | < file 5.02-1 (bookworm) | file 5.02-1 (bookworm) |
| debian | file | < file 5.03-1 (bookworm) | file 5.03-1 (bookworm) |
| file_project | file | >= 0 < 5.03-1 | 5.03-1 |
| file_project | file | >= 0 < 5.02-1 | 5.02-1 |
| file_project | file | >= 0 < 5.03-1 | 5.03-1 |
| file_project | file | >= 0 < 5.02-1 | 5.02-1 |
| file_project | file | >= 0 < 5.03-1 | 5.03-1 |
| file_project | file | >= 0 < 5.02-1 | 5.02-1 |
| file_project | file | >= 0 < 5.03-1 | 5.03-1 |
| file_project | file | >= 0 < 5.02-1 | 5.02-1 |
| linux | linux_kernel | < 6.12.65 | 6.12.65 |
| linux | linux_kernel | >= 0 < 6.1.160 | 6.1.160 |
| linux | linux_kernel | >= 6.2.0 < 6.6.120 | 6.6.120 |
| linux | linux_kernel | >= 6.7.0 < 6.18.4 | 6.18.4 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
mptcp: fallback earlier on simult connection
osv·2026-01-13·CVSS 5.5
CVE-2025-71088 mptcp: fallback earlier on simult connection
mptcp: fallback earlier on simult connection
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fallback earlier on simult connection
Syzkaller reports a simult-connect race leading to inconsistent fallback
status:
WARNING: CPU: 3 PID: 33 at net/mptcp/subflow.c:1515 subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Modules linked in:
CPU: 3 UID: 0 PID: 33 Comm: ksoftirqd/3 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Code: 89 ee e8 78 61 3c f6 40 84 ed 75 21 e8 8e 66 3c f6 44 89 fe bf 07 00 00 00 e8 c1 61 3c f6 41 83 ff 07 74 09 e8 76 66 3c f6 90 0b 90 e8 6d 66 3c f6 48 89 df e8 e5 ad ff ff 31 ff 89
GHSA
GHSA-5vxx-g7fm-qfjw: Heap-based buffer overflow in the cdf_read_sat function in src/cdf
ghsa_unreviewed·2022-05-03
CVE-2009-1515 [MEDIUM] CWE-119 GHSA-5vxx-g7fm-qfjw: Heap-based buffer overflow in the cdf_read_sat function in src/cdf
Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.
GHSA
GHSA-47c7-xq7g-3v46: Multiple buffer overflows in Christos Zoulas file before 5
ghsa_unreviewed·2022-05-02·CVSS 6.8
CVE-2009-2830 [MEDIUM] CWE-119 GHSA-47c7-xq7g-3v46: Multiple buffer overflows in Christos Zoulas file before 5
Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Common Document Format (CDF) file. NOTE: this might overlap CVE-2009-1515.
OSV
CVE-2009-2830: Multiple buffer overflows in Christos Zoulas file before 5
osv·2009-11-10·CVSS 6.8
CVE-2009-2830 [MEDIUM] CVE-2009-2830: Multiple buffer overflows in Christos Zoulas file before 5
Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Common Document Format (CDF) file. NOTE: this might overlap CVE-2009-1515.
OSV
CVE-2009-1515: Heap-based buffer overflow in the cdf_read_sat function in src/cdf
osv·2009-05-04·CVSS 6.8
CVE-2009-1515 [MEDIUM] CVE-2009-1515: Heap-based buffer overflow in the cdf_read_sat function in src/cdf
Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.
Red Hat
kernel: Linux kernel: Denial of Service via MPTCP race condition
vendor_redhat·2026-01-13·CVSS 5.5
CVE-2025-71088 [MEDIUM] CWE-366 kernel: Linux kernel: Denial of Service via MPTCP race condition
kernel: Linux kernel: Denial of Service via MPTCP race condition
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fallback earlier on simult connection
Syzkaller reports a simult-connect race leading to inconsistent fallback
status:
WARNING: CPU: 3 PID: 33 at net/mptcp/subflow.c:1515 subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Modules linked in:
CPU: 3 UID: 0 PID: 33 Comm: ksoftirqd/3 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Code: 89 ee e8 78 61 3c f6 40 84 ed 75 21 e8 8e 66 3c f6 44 89 fe bf 07 00 00 00 e8 c1 61 3c f6 41 83 ff 07 74 09 e8 76 66 3c f6 90 0b 90 e8 6d 66 3c f6 48 89 df e8 e5 a
Red Hat
file: heap-based buffer overflow in cdf_read_sat()
vendor_redhat·2009-04-27·CVSS 6.8
CVE-2009-1515 [MEDIUM] CWE-122 file: heap-based buffer overflow in cdf_read_sat()
file: heap-based buffer overflow in cdf_read_sat()
Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.
Debian
CVE-2009-1515: file - Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos...
vendor_debian·2009·CVSS 6.8
CVE-2009-1515 [MEDIUM] CVE-2009-1515: file - Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos...
Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 5.02-1)
bullseye: resolved (fixed in 5.02-1)
forky: resolved (fixed in 5.02-1)
sid: resolved (fixed in 5.02-1)
trixie: resolved (fixed in 5.02-1)
Debian
CVE-2009-2830: file - Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X ...
vendor_debian·2009·CVSS 6.8
CVE-2009-2830 [MEDIUM] CVE-2009-2830: file - Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X ...
Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Common Document Format (CDF) file. NOTE: this might overlap CVE-2009-1515.
Scope: local
bookworm: resolved (fixed in 5.03-1)
bullseye: resolved (fixed in 5.03-1)
forky: resolved (fixed in 5.03-1)
sid: resolved (fixed in 5.03-1)
trixie: resolved (fixed in 5.03-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1515 file: heap-based buffer overflow in cdf_read_sat()
bugzilla·2009-04-27·CVSS 6.8
CVE-2009-1515 [MEDIUM] CVE-2009-1515 file: heap-based buffer overflow in cdf_read_sat()
CVE-2009-1515 file: heap-based buffer overflow in cdf_read_sat()
A bug reported to Debian [1] affects file 5.x which is only available in the forthcoming Fedora 11. When running file on an MSI file, file crashes. The following link causes a crash with file 5.x: http://www.python.org/ftp/python/2.6.2/python-2.6.2.msi. Tested with file 4.x on Fedora 10, RHEL5, and RHEL4 and the file is properly identified.
% file python-2.6.2.msi
*** glibc detected *** file: munmap_chunk(): invalid pointer: 0x0000000001a8cf50 ***
There is currently no patch to correct the issue that I can find.
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=525820
Discussion:
hello,
I have reported the issue to file upstream
---
Secunia has issued an advisory about this: http://secunia.com/advisories/34881/
--
Wiz
CVE-2025-71088 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2025-71088 [MEDIUM] CVE-2025-71088 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-71088 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fallback earlier on simult connection
Syzkaller reports a simult-connect race leading to inconsistent fallback
status:
WARNING: CPU: 3 PID: 33 at net/mptcp/subflow.c:1515 subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Modules linked in:
CPU: 3 UID: 0 PID: 33 Comm: ksoftirqd/3 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
RIP: 0010:subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515
Code: 89 ee e8 78 61 3c f6 40 84 ed 75 21 e8 8e 66 3c f6 44 89 fe bf 07 00 00 00 e8 c1 61 3c f6 41 83 ff 07 74 09 e8 76 66 3c f6 90 0b 90 e8 6d 66 3c f6 48 89
ftp://ftp.astron.com/pub/file/file-5.01.tar.gzhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=515603http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=525820http://mx.gw.com/pipermail/file/2009/000379.htmlhttp://secunia.com/advisories/34881http://www.mandriva.com/security/advisories?name=MDVSA-2009:129http://www.osvdb.org/54100http://www.securityfocus.com/bid/34745ftp://ftp.astron.com/pub/file/file-5.01.tar.gzhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=515603http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=525820http://mx.gw.com/pipermail/file/2009/000379.htmlhttp://secunia.com/advisories/34881http://www.mandriva.com/security/advisories?name=MDVSA-2009:129http://www.osvdb.org/54100http://www.securityfocus.com/bid/34745
2009-05-04
Published