FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-1791

This CVE name corresponds to:

Entered Topic
2009-05-30 libsndfile -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-1791
Phase Assigned(20090526)

Description

Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.

References

Source Reference
CONFIRM http://www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/
CONFIRM http://www.mega-nerd.com/libsndfile/
DEBIAN DSA-1814
GENTOO GLSA-200905-09
MANDRIVA MDVSA-2009:132
BID 34978
SECUNIA 35076
SECUNIA 35247
SECUNIA 35443
VUPEN ADV-2009-1324
XF libsndfile-aiff-voc-bo(50541)