Vulnerability Name: | CVE-2009-0490 (CCN-47716) | ||||||||
Assigned: | 2009-01-01 | ||||||||
Published: | 2009-01-01 | ||||||||
Updated: | 2022-02-07 | ||||||||
Summary: | Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 7.3 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-787 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Audacity Web site Audacity: Free Audio Editor and Recorder Source: CONFIRM Type: Third Party Advisory http://bugs.gentoo.org/show_bug.cgi?id=253493 Source: MITRE Type: CNA CVE-2009-0490 Source: SUSE Type: Third Party Advisory SUSE-SR:2009:004 Source: MLIST Type: Broken Link [audacity-devel] 20090110 Audacity "String_parse::get_nonspace_quoted()" Buffer Overflow Source: OSVDB Type: Broken Link 51070 Source: CCN Type: SA33356 Audacity "String_parse::get_nonspace_quoted()" Buffer Overflow Source: SECUNIA Type: Broken Link 33356 Source: CCN Type: GLSA-200903-03 Audacity: User-assisted execution of arbitrary code Source: CCN Type: OSVDB ID: 51070 Audacity lib-src/allegro/strparse.cpp String_parse::get_nonspace_quoted() Function Crafted GRO File Handling Overflow Source: BID Type: Broken Link, Third Party Advisory, VDB Entry 33090 Source: CCN Type: BID-33090 Audacity 'lib-src/allegro/strparse.cpp' Buffer Overflow Vulnerability Source: VUPEN Type: Broken Link ADV-2009-0008 Source: XF Type: UNKNOWN audacity-stringparse-bo(47716) Source: EXPLOIT-DB Type: Third Party Advisory, VDB Entry 7634 Source: SUSE Type: SUSE-SR:2009:004 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |