CVE-2009-3995: Buffer Overflow
Multiple heap-based buffer overflow vulnerabilities were found in libmikmod. These flaws could allow a remote attacker able to coerce a local user using an application linked against libmikmod, to open an Impulse Tracker, crafted samples, or an Ultratracker file, to execute arbitrary code with the privileges of the user running the application.
CVE-2009-3995:
Multiple heap-based buffer overflows in INMOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file. NOTE: some of these details are obtained from third party information.
CVE-2009-3996:
Heap-based buffer overflow in INMOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file.
References:
http://www.vupen.com/english/advisories/2009/3575 http://secunia.com/secuniaresearch/2009-55/
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3995?
CVE-2009-3995 has a high severity rating due to potential remote code execution risks.
How do I fix CVE-2009-3995?
To fix CVE-2009-3995, upgrade to Winamp version 5.57 or later and ensure libmikmod is updated to version 3.1.6-33 or later.
What vulnerabilities does CVE-2009-3995 exploit?
CVE-2009-3995 exploits multiple heap-based buffer overflows in IN_MOD.DLL allowing attackers to run arbitrary code.
Which software versions are affected by CVE-2009-3995?
CVE-2009-3995 affects multiple versions of Winamp prior to 5.57 and libmikmod versions before 3.1.12.
What are the risks associated with CVE-2009-3995?
The risks associated with CVE-2009-3995 include unauthorized remote code execution and potential control over the affected system.