Vulnerabilities > CVE-2009-0490 - Out-of-bounds Write vulnerability in Audacityteam Audacity

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
audacityteam
CWE-787
nessus
exploit available

Summary

Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string.

Common Weakness Enumeration (CWE)

Exploit-Db

  • descriptionAudacity 1.2.6 (.gro File) Local Buffer Overflow PoC. CVE-2009-0490. Dos exploit for windows platform
    fileexploits/windows/dos/7634.pl
    idEDB-ID:7634
    last seen2016-02-01
    modified2009-01-01
    platformwindows
    port
    published2009-01-01
    reporterHoussamix
    sourcehttps://www.exploit-db.com/download/7634/
    titleAudacity 1.2.6 - .gro Local Buffer Overflow PoC
    typedos
  • descriptionAudacity <= 1.2 (.gro File) Universal BOF Exploit (egg hunter). CVE-2009-0490. Local exploit for windows platform
    idEDB-ID:9501
    last seen2016-02-01
    modified2009-08-24
    published2009-08-24
    reportermr_me
    sourcehttps://www.exploit-db.com/download/9501/
    titleAudacity <= 1.2 - .gro Universal BoF Exploit egg hunter
  • descriptionAudacity 1.2.6 (gro File) Buffer overflow Exploit. CVE-2009-0490. Local exploit for windows platform
    idEDB-ID:10322
    last seen2016-02-01
    modified2009-12-05
    published2009-12-05
    reporterEncrypt3d.M!nd
    sourcehttps://www.exploit-db.com/download/10322/
    titleAudacity 1.2.6 gro File Buffer Overflow Exploit

Nessus

  • NASL familyMandriva Local Security Checks
    NASL idMANDRIVA_MDVSA-2009-055.NASL
    descriptionA vulnerability has been identified and corrected in audacity : Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string (CVE-2009-0490). The updated packages have been patched to prevent this.
    last seen2020-06-01
    modified2020-06-02
    plugin id36403
    published2009-04-23
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/36403
    titleMandriva Linux Security Advisory : audacity (MDVSA-2009:055)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_0_AUDACITY-090212.NASL
    descriptionSpecially crafted GRO files could cause a stack based buffer in audacity (CVE-2009-0490).
    last seen2020-06-01
    modified2020-06-02
    plugin id39917
    published2009-07-21
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/39917
    titleopenSUSE Security Update : audacity (audacity-523)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200903-03.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200903-03 (Audacity: User-assisted execution of arbitrary code) Houssamix discovered a boundary error in the String_parse::get_nonspace_quoted() function in lib-src/allegro/strparse.cpp. Impact : A remote attacker could entice a user into importing a specially crafted *.gro file, resulting in the execution of arbitrary code or a Denial of Service. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id35793
    published2009-03-08
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/35793
    titleGLSA-200903-03 : Audacity: User-assisted execution of arbitrary code
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_1_AUDACITY-090212.NASL
    descriptionSpecially crafted GRO files could cause a stack based buffer in audacity (CVE-2009-0490).
    last seen2020-06-01
    modified2020-06-02
    plugin id40190
    published2009-07-21
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/40190
    titleopenSUSE Security Update : audacity (audacity-523)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_AUDACITY-5997.NASL
    descriptionSpecially crafted GRO files could cause a stack based buffer in audacity (CVE-2009-0490).
    last seen2020-06-01
    modified2020-06-02
    plugin id35676
    published2009-02-13
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/35676
    titleopenSUSE 10 Security Update : audacity (audacity-5997)