Integer Overflow Vulnerability in libmodplug Affecting Multiple Products
CVE-2009-1438

Currently unrated

Key Information:

Vendor
CVE Published:
27 April 2009

What is CVE-2009-1438?

The integer overflow vulnerability in the CSoundFile::ReadMed function of libmodplug allows attackers to execute arbitrary code by exploiting crafted MED files. This occurs when processing specific song comments or names, leading to a heap-based buffer overflow. Various products, including gstreamer-plugins and TTPlayer, are impacted, with potential risks that have been observed in real-world attacks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.