FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-1788

This CVE name corresponds to:

Entered Topic
2009-05-30 libsndfile -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-1788
Phase Assigned(20090526)

Description

Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.

References

Source Reference
MISC http://trapkit.de/advisories/TKADV2009-006.txt
CONFIRM http://www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/
CONFIRM http://www.mega-nerd.com/libsndfile/
DEBIAN DSA-1814
GENTOO GLSA-200905-09
MANDRIVA MDVSA-2009:132
BID 34978
SECUNIA 35076
SECUNIA 35126
SECUNIA 35247
SECUNIA 35443
VUPEN ADV-2009-1324
VUPEN ADV-2009-1348
XF libsndfile-aiff-voc-bo(50541)
XF libsndfile-voc-bo(50827)