6.8
CVE-2009-0475
- EPSS 2.2%
- Veröffentlicht 11.02.2009 00:30:02
- Zuletzt bearbeitet 16.06.2026 23:05:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a crafted MP3 file that triggers heap corruption.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.2% | 0.802 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://android.git.kernel.org/?p=platform/external/opencore.git%3Ba=commit%3Bh=7b466cd0ecfdba72c4cbd0f3a8c2001141376b0f
http://review.source.android.com/Gerrit#change%2C8815
http://www.ocert.org/advisories/ocert-2009-002.html
http://www.securityfocus.com/archive/1/500750/100/0/threaded
http://www.securityfocus.com/bid/33673