Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-3996
HistoryDec 18, 2009 - 12:00 a.m.

CVE-2009-3996

2009-12-1800:00:00
ubuntu.com
ubuntu.com
11

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.199

Percentile

96.3%

Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in)
in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers
to execute arbitrary code via an Ultratracker file.

Bugs

Notes

Author Note
mdeslaur fixed by CVE-2009-3995f.patch in 3.1.11-6.2
OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchlibmikmod<Β 3.1.11-6ubuntu3.8.04.1UNKNOWN
ubuntu9.04noarchlibmikmod<Β 3.1.11-6ubuntu3.9.04.1UNKNOWN
ubuntu9.10noarchlibmikmod<Β 3.1.11-6ubuntu4.1UNKNOWN
ubuntu10.04noarchlibmikmod<Β 3.1.11-6.1ubuntu0.1UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.199

Percentile

96.3%