CVE-2009-1788Improper Restriction of Operations within the Bounds of a Memory Buffer in Libsndfile

Severity
9.3CRITICALNVD
EPSS
8.6%
top 7.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26
Latest updateMay 2

Description

Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

debiandebian/libsndfile< libsndfile 1.0.20-1 (bookworm)
Debianlibsndfile_project/libsndfile< 1.0.20-1+3
NVDmega-nerd/libsndfile5 versions+4
NVDnullsoft/winamp7 versions+6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6589-vpjv-7v45: Heap-based buffer overflow in voc_read_header in libsndfile 12022-05-02
OSV
CVE-2009-1788: Heap-based buffer overflow in voc_read_header in libsndfile 12009-05-26

📋Vendor Advisories

3
Ubuntu
libsndfile vulnerabilities2009-10-15
Red Hat
libsndfile VOC file heap based buffer overflow2009-05-15
Debian
CVE-2009-1788: libsndfile - Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.1...2009

💬Community

2
Bugzilla
CVE-2009-1788 CVE-2009-1791 Multiple libsndfile vulnerabilities [Fedora epel-5]2010-12-20
Bugzilla
CVE-2009-1788 libsndfile VOC file heap based buffer overflow2009-05-26
CVE-2009-1788 — Debian Libsndfile vulnerability | cvebase