cbcvebase.
CVE-2009-1515
published 2009-05-04

CVE-2009-1515: Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.

Affected

19 ranges
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x
applemac_os_x_server
applemac_os_x_server
christos_zoulasfile
debianfile< file 5.02-1 (bookworm)file 5.02-1 (bookworm)
debianfile< file 5.03-1 (bookworm)file 5.03-1 (bookworm)
file_projectfile>= 0 < 5.03-15.03-1
file_projectfile>= 0 < 5.02-15.02-1
file_projectfile>= 0 < 5.03-15.03-1
file_projectfile>= 0 < 5.02-15.02-1
file_projectfile>= 0 < 5.03-15.03-1
file_projectfile>= 0 < 5.02-15.02-1
file_projectfile>= 0 < 5.03-15.03-1
file_projectfile>= 0 < 5.02-15.02-1
linuxlinux_kernel< 6.12.656.12.65
linuxlinux_kernel>= 0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.18.46.18.4

CVSS provenance

nvd6.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM