[Secure-testing-team] Bug#575742: CVE-2009-3995 CVE-2009-3996: Multiple heap-based buffer overflows
Giuseppe Iuculano
iuculano at debian.org
Sun Mar 28 21:11:09 UTC 2010
Package: libmikmod
Severity: serious
Tags: security
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
the following CVE (Common Vulnerabilities & Exposures) ids were
published for libmikmod.
CVE-2009-3995[0]:
| Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module
| Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to
| execute arbitrary code via (1) crafted samples or (2) crafted
| instrument definitions in an Impulse Tracker file.
CVE-2009-3996[1]:
| Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder
| Plug-in) in Winamp before 5.57 might allow remote attackers to execute
| arbitrary code via an Ultratracker file.
If you fix the vulnerabilities please also make sure to include the
CVE ids in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3995
http://security-tracker.debian.org/tracker/CVE-2009-3995
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3996
http://security-tracker.debian.org/tracker/CVE-2009-3996
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAkuvxeoACgkQNxpp46476aqYowCZAYzx91cv2k7Ewj5LdSDx75vE
0hkAni+D8rRq+jIw0gDD9ro1gGz3gl38
=fwh7
-----END PGP SIGNATURE-----
More information about the Secure-testing-team
mailing list