CVE-2009-1438 describes an integer overflow in the CSoundFile::ReadMed function within libmodplug, affecting products like gstreamer-plugins and TTPlayer. This vulnerability allows unauthenticated attackers to execute arbitrary code via specially crafted MED files, leading to a heap-based buffer overflow. With a CVSS score of 7.5, it poses a significant risk of partial confidentiality, integrity, and availability compromise. Although exploited in the wild in August 2008, there is currently no public exploit code, Metasploit module, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.8.5CPE matchmatch criteria | cpe:2.3:a:konstanty_bialkowski:libmodplug:*:*:*:*:*:*:*:* | ||
0.8CPE matchmatch criteria | cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8:*:*:*:*:*:*:* | ||
0.8.4CPE matchmatch criteria | cpe:2.3:a:konstanty_bialkowski:libmodplug:0.8.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.