CVE-2009-1788

Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
mega-nerdlibsndfile
1.0.15
mega-nerdlibsndfile
1.0.16
mega-nerdlibsndfile
1.0.17
mega-nerdlibsndfile
1.0.18
mega-nerdlibsndfile
1.0.19
nullsoftwinamp
5.5
nullsoftwinamp
5.51
nullsoftwinamp
5.52
nullsoftwinamp
5.54
nullsoftwinamp
5.55
nullsoftwinamp
5.541
nullsoftwinamp
5.552
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libsndfile
bullseye
1.0.31-2
fixed
bookworm
1.2.0-1
fixed
sid
1.2.2-1
fixed
trixie
1.2.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libsndfile
jaunty
Fixed 1.0.17-4ubuntu1.1
released
intrepid
Fixed 1.0.17-4ubuntu0.8.10.2
released
hardy
Fixed 1.0.17-4ubuntu0.8.04.2
released
dapper
ignored