CVE-2009-1515: Buffer Overflow
Heap-based buffer overflow in the cdfreadsat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1515?
CVE-2009-1515 has a critical severity due to the potential for remote code execution.
How do I fix CVE-2009-1515?
To fix CVE-2009-1515, update to a patched version of the Christos Zoulas file that addresses the heap-based buffer overflow.
What software is affected by CVE-2009-1515?
CVE-2009-1515 affects version 5.00 of the Christos Zoulas file software.
What type of attacks can exploit CVE-2009-1515?
CVE-2009-1515 can be exploited by remote attackers using crafted compound document files, such as .msi, .doc, or .mpp files.
Is user interaction required to exploit CVE-2009-1515?
Yes, user interaction is required for CVE-2009-1515 as the crafted files must be opened by the user to trigger the vulnerability.