Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Owen Arden

Researcher fromSecurity Evaluators
#40348of 53,633
6.8Total CVSS
Vulnerabilities · 1
PT-2009-3129
6.8
2009-02-11
Core · Opencore · CVE-2009-0475
**Name of the Vulnerable Software and Affected Versions** OpenCORE versions 2.0 and earlier **Description** The issue is related to an integer underflow in the Huffman decoding functionality, specifically in the pvmp3 huffman parsing.cpp file. This allows remote attackers to cause a denial of service, resulting in a process crash, and potentially execute arbitrary code via a crafted MP3 file that triggers heap corruption. **Recommendations** For OpenCORE versions 2.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.