CVE-2009-4835: Medium severity mega-nerd libsndfile vulnerability
Published May 5, 2010
·Updated
The (1) htkreadheader, (2) alawinit, (3) ulawinit, (4) pcminit, (5) float32init, and (6) sdsreadheader functions in libsndfile 1.0.20 allow context-dependent attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted audio file.
Affected Software
1 affected component
mega-nerd libsndfile=1.0.20
Event History
May 5, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 6, 2010
Data Sourced
via NVD·12:47 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4835?
CVE-2009-4835 is considered a medium severity vulnerability due to its ability to cause a denial of service.
2
How do I fix CVE-2009-4835?
To fix CVE-2009-4835, upgrade libsndfile to version 1.0.21 or later.
3
What systems are affected by CVE-2009-4835?
CVE-2009-4835 affects libsndfile version 1.0.20.
4
What kind of vulnerability is CVE-2009-4835?
CVE-2009-4835 is a denial of service vulnerability caused by divide-by-zero errors in specific functions.
5
Can CVE-2009-4835 be exploited remotely?
Yes, CVE-2009-4835 can be exploited by context-dependent attackers through crafted audio files.