{
  "public_date" : "2008-02-25T00:00:00Z",
  "bugzilla" : {
    "description" : "libmodplug: Integer overflow in the MED files loading routine",
    "id" : "496834",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=496834"
  },
  "cwe" : "CWE-190",
  "details" : [ "Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based buffer overflow, as exploited in the wild in August 2008." ],
  "statement" : "The impact of this flaw is limited to application crash, not allowing code execution. Red Hat does not consider a user-assisted crash of a client application such as media players using GStreamer framework to be a security issue.\nFor further details, see: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-1438",
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2009-1438\nhttps://nvd.nist.gov/vuln/detail/CVE-2009-1438" ],
  "name" : "CVE-2009-1438",
  "csaw" : false
}