Unrated severityNVD Advisory· Published May 26, 2009· Updated Apr 23, 2026
CVE-2009-1788
CVE-2009-1788
Description
Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.
Affected products
12cpe:2.3:a:mega-nerd:libsndfile:1.0.15:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:mega-nerd:libsndfile:1.0.15:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.16:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.17:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.18:*:*:*:*:*:*:*
- cpe:2.3:a:mega-nerd:libsndfile:1.0.19:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:5.5:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:nullsoft:winamp:5.5:*:*:*:*:*:*:*
- cpe:2.3:a:nullsoft:winamp:5.51:*:*:*:*:*:*:*
- cpe:2.3:a:nullsoft:winamp:5.52:*:*:*:*:*:*:*
- cpe:2.3:a:nullsoft:winamp:5.54:*:*:*:*:*:*:*
- cpe:2.3:a:nullsoft:winamp:5.55:*:*:*:*:*:*:*
- cpe:2.3:a:nullsoft:winamp:5.541:*:*:*:*:*:*:*
- cpe:2.3:a:nullsoft:winamp:5.552:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/nvdPatchVendor Advisory
- www.mega-nerd.com/libsndfile/nvdPatch
- www.securityfocus.com/bid/34978nvdPatch
- www.vupen.com/english/advisories/2009/1324nvdPatchVendor Advisory
- www.vupen.com/english/advisories/2009/1348nvdPatchVendor Advisory
- trapkit.de/advisories/TKADV2009-006.txtnvdExploit
- secunia.com/advisories/35076nvdVendor Advisory
- secunia.com/advisories/35126nvd
- secunia.com/advisories/35247nvd
- secunia.com/advisories/35443nvd
- security.gentoo.org/glsa/glsa-200905-09.xmlnvd
- www.debian.org/security/2009/dsa-1814nvd
- www.mandriva.com/security/advisoriesnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/50541nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/50827nvd
News mentions
0No linked articles in our index yet.