Unrated severityNVD Advisory· Published Jun 16, 2009· Updated Apr 23, 2026
CVE-2009-1391
CVE-2009-1391
Description
Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild by Trojan.Downloader-71014 in June 2009.
Affected products
13cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:*:*:*:*:*:*:*:*range: <=2.015
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.001:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.002:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.003:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.004:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.005:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.006:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.008:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.009:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.010:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.011:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.012:*:*:*:*:*:*:*
- cpe:2.3:a:paul_marquess:compress-raw-zlib_perl_module:2.014:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
18- www.vupen.com/english/advisories/2009/1571nvdPatchVendor Advisory
- article.gmane.org/gmane.mail.virus.amavis.user/33638nvdExploit
- www.securityfocus.com/bid/35307nvdExploitPatch
- bugzilla.redhat.com/show_bug.cginvdExploit
- secunia.com/advisories/35422nvdVendor Advisory
- article.gmane.org/gmane.mail.virus.amavis.user/33635nvd
- lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.htmlnvd
- osvdb.org/55041nvd
- secunia.com/advisories/35685nvd
- secunia.com/advisories/35689nvd
- secunia.com/advisories/35876nvd
- security.gentoo.org/glsa/glsa-200908-07.xmlnvd
- thread.gmane.org/gmane.mail.virus.amavis.user/33635nvd
- www.mandriva.com/security/advisoriesnvd
- bugs.gentoo.org/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/51062nvd
- usn.ubuntu.com/794-1/nvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00607.htmlnvd
News mentions
0No linked articles in our index yet.