[Secure-testing-team] Bug#575742: CVE-2009-3995 CVE-2009-3996: Multiple heap-based buffer overflows

Giuseppe Iuculano iuculano at debian.org
Sun Mar 28 21:11:09 UTC 2010


Package: libmikmod
Severity: serious
Tags: security

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Hi,
the following CVE (Common Vulnerabilities & Exposures) ids were
published for libmikmod.

CVE-2009-3995[0]:
| Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module
| Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to
| execute arbitrary code via (1) crafted samples or (2) crafted
| instrument definitions in an Impulse Tracker file.

CVE-2009-3996[1]:
| Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder
| Plug-in) in Winamp before 5.57 might allow remote attackers to execute
| arbitrary code via an Ultratracker file.

If you fix the vulnerabilities please also make sure to include the
CVE ids in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3995
    http://security-tracker.debian.org/tracker/CVE-2009-3995
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3996
    http://security-tracker.debian.org/tracker/CVE-2009-3996


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkuvxeoACgkQNxpp46476aqYowCZAYzx91cv2k7Ewj5LdSDx75vE
0hkAni+D8rRq+jIw0gDD9ro1gGz3gl38
=fwh7
-----END PGP SIGNATURE-----





More information about the Secure-testing-team mailing list