Giuseppe Iuculano
2010-Mar-28 21:11 UTC
[Secure-testing-team] Bug#575742: CVE-2009-3995 CVE-2009-3996: Multiple heap-based buffer overflows
Package: libmikmod Severity: serious Tags: security -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities & Exposures) ids were published for libmikmod. CVE-2009-3995[0]: | Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module | Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to | execute arbitrary code via (1) crafted samples or (2) crafted | instrument definitions in an Impulse Tracker file. CVE-2009-3996[1]: | Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder | Plug-in) in Winamp before 5.57 might allow remote attackers to execute | arbitrary code via an Ultratracker file. If you fix the vulnerabilities please also make sure to include the CVE ids in your changelog entry. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3995 http://security-tracker.debian.org/tracker/CVE-2009-3995 [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3996 http://security-tracker.debian.org/tracker/CVE-2009-3996 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkuvxeoACgkQNxpp46476aqYowCZAYzx91cv2k7Ewj5LdSDx75vE 0hkAni+D8rRq+jIw0gDD9ro1gGz3gl38 =fwh7 -----END PGP SIGNATURE-----