CVE-2009-1438

EPSS 2.5%

libmodplug - arbitrary code execution

發布日:2009/4/27修改日:2026/4/28
也稱為:DEBIAN-CVE-2009-1438

描述

Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based buffer overflow, as exploited in the wild in August 2008.

受影響套件(3)

參考連結(1)