PT-2009-6196 · Iohannes Zahl+3 · Libmikmod+3

Published

2009-12-18

·

Updated

2018-10-10

·

CVE-2009-3996

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Winamp versions prior to 5.57 libmikmod version 3.1.12
Description A heap-based buffer overflow issue exists, potentially allowing remote attackers to execute arbitrary code via an Ultratracker file. This issue is related to the Module Decoder Plug-in (IN MOD.DLL) in affected software.
Recommendations For Winamp versions prior to 5.57, update to version 5.57 or later to resolve the issue. For libmikmod version 3.1.12, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2126
CVE-2009-3996
DSA-2071-1
OPENSUSE-SU-2024:10305-1
RHSA-2010:0720
RHSA-2010_0720

Affected Products

Alt Linux
Red Hat
Winamp
Libmikmod