Audacity 'lib-src/allegro/strparse.cpp' Buffer Overflow Vulnerability
BID:33090
Info
Audacity 'lib-src/allegro/strparse.cpp' Buffer Overflow Vulnerability
| Bugtraq ID: | 33090 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0490 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2009 12:00AM |
| Updated: | Aug 28 2009 05:22PM |
| Credit: | Houssamix <br> |
| Vulnerable: |
S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 Pardus Linux 2009 0 Pardus Linux 2008 0 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Audacity Audacity 1.2.6 |
| Not Vulnerable: | |
Discussion
Audacity 'lib-src/allegro/strparse.cpp' Buffer Overflow Vulnerability
Audacity is prone a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
NOTE (August 25, 2009): This BID had wrongly referred to Audacity 1.6.2, but now correctly refers to the affected version: Audacity 1.2.6.
Audacity 1.2.6 is vulnerable; other versions may also be affected.
Audacity is prone a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
NOTE (August 25, 2009): This BID had wrongly referred to Audacity 1.6.2, but now correctly refers to the affected version: Audacity 1.2.6.
Audacity 1.2.6 is vulnerable; other versions may also be affected.
Exploit / POC
Audacity 'lib-src/allegro/strparse.cpp' Buffer Overflow Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit are available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit are available:
Solution / Fix
Audacity 'lib-src/allegro/strparse.cpp' Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for details.
Mandriva Linux Mandrake 2009.0 x86_64
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2008.0 x86_64
Mandriva Linux Mandrake 2008.1
Mandriva Linux Mandrake 2008.0
Mandriva Linux Mandrake 2009.0
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
Solution:
Updates are available. Please see the references for details.
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva audacity-1.3.5-3.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva audacity-1.3.4-7.2mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva audacity-1.3.3-1.2mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva audacity-1.3.4-7.2mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0
-
Mandriva audacity-1.3.3-1.2mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva audacity-1.3.5-3.1mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 3.0 x86_64
-
Mandriva audacity-1.2.0-1.2.C30mdk.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 3.0
-
Mandriva audacity-1.2.0-1.2.C30mdk.i586.rpm
http://www.mandriva.com/en/download/
References
Audacity 'lib-src/allegro/strparse.cpp' Buffer Overflow Vulnerability
References:
References:
- Audacity Homepage (Audacity)