6.8
CVE-2009-1391
- EPSS 19.4%
- Published 16.06.2009 23:30:00
- Last modified 09.04.2025 00:30:58
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild by Trojan.Downloader-71014 in June 2009.
Data is provided by the National Vulnerability Database (NVD)
Paul Marquess ≫ Compress-raw-zlib Perl Module Version <= 2.015
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.001
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.002
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.003
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.004
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.005
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.006
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.008
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.009
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.010
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.011
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.012
Paul Marquess ≫ Compress-raw-zlib Perl Module Version2.014
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 19.4% | 0.948 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|