Unrated severityNVD Advisory· Published Mar 5, 2009· Updated Apr 23, 2026
CVE-2009-0186
CVE-2009-0186
Description
Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.
Affected products
25cpe:2.3:a:mega-nerd:libsndfile:*:*:*:*:*:*:*:*+ 22 more
- cpe:2.3:a:mega-nerd:libsndfile:*:*:*:*:*:*:*:*range: <=1.0.18
- cpe:2.3:a:mega-nerd:libsndfile:0.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:0.0.28:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.0:rc6:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.17:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
20- secunia.com/advisories/33980nvdVendor Advisory
- secunia.com/advisories/33981nvdVendor Advisory
- secunia.com/secunia_research/2009-7/nvdVendor Advisory
- secunia.com/secunia_research/2009-8/nvdVendor Advisory
- www.vupen.com/english/advisories/2009/0584nvdVendor Advisory
- www.vupen.com/english/advisories/2009/0585nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlnvd
- secunia.com/advisories/34316nvd
- secunia.com/advisories/34526nvd
- secunia.com/advisories/34642nvd
- secunia.com/advisories/34791nvd
- security.gentoo.org/glsa/glsa-200904-16.xmlnvd
- www.debian.org/security/2009/dsa-1742nvd
- www.mega-nerd.com/libsndfile/NEWSnvd
- www.securityfocus.com/archive/1/501399/100/0/threadednvd
- www.securityfocus.com/archive/1/501413/100/0/threadednvd
- www.securityfocus.com/bid/33963nvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/USN-749-1nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/49038nvd
News mentions
0No linked articles in our index yet.