Novell Home

CVE-2009-1438

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-1438 at MITRE

Description

Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based buffer overflow, as exploited in the wild in August 2008.

NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)

Novell/SUSE information

Novell Bugzilla entry: 496541, 498828

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
Novell Linux Desktop 9 for x86
Novell Linux Desktop 9 for x86_64
  • gstreamer-plugins >= 0.8.1-8.10
  • gstreamer-plugins-default >= 0.8.1-8.10
  • gstreamer-plugins-devel >= 0.8.1-8.10
  • gstreamer-plugins-excess >= 0.8.1-8.10
  • gstreamer-plugins-extra >= 0.8.1-8.10
sles9-nld.x86-64
sles9-nld.x86
YOU Patch Nr: 12420
openSUSE 10.3
  • gstreamer010-plugins-bad >= 0.10.5-36.2
  • gstreamer010-plugins-bad-devel >= 0.10.5-36.2
  • gstreamer010-plugins-bad-doc >= 0.10.5-36.2

© 2012 Novell