Candidate: CVE-2009-1791 PublicDate: 2009-05-26 17:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1791 https://ubuntu.com/security/notices/USN-849-1 Description: Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Erik de Castro Lopo (upstream) Assigned-to: jdstrand CVSS: Patches_libsndfile: upstream: http://www.mega-nerd.com/erikd/Blog/files/voc-aiff-patch-1.0.17.diff upstream_libsndfile: released (1.0.20-1) dapper_libsndfile: ignored (reached end-of-life) hardy_libsndfile: released (1.0.17-4ubuntu0.8.04.2) intrepid_libsndfile: released (1.0.17-4ubuntu0.8.10.2) jaunty_libsndfile: released (1.0.17-4ubuntu1.1) devel_libsndfile: not-affected (1.0.20-1ubuntu1)