Novell Home

CVE-2009-1791

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-1791 at MITRE

Description

Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.

NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)

Novell/SUSE information

Novell Bugzilla entry: 504434

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.3
  • libsndfile >= 1.0.17-81.4
  • libsndfile-32bit >= 1.0.17-81.4
  • libsndfile-64bit >= 1.0.17-81.4
  • libsndfile-devel >= 1.0.17-81.4
  • libsndfile-octave >= 1.0.17-81.4
  • libsndfile-progs >= 1.0.17-81.4

List of products where fixes are in QA

© 2012 Novell