CVE-2009-0475
Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a crafted MP3 file that triggers…
Does this matter?
Lower severity and a low EPSS score (2.20%). Track it; it rarely justifies an emergency change on its own.
Description
Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a crafted MP3 file that triggers heap corruption.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.20% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- android/opencore
- Source
- cve@mitre.org
References
- http://android.git.kernel.org/?p=platform/external/opencore.git%3Ba=commit%3Bh=7b466cd0ecfdba72c4cbd0f3a8c2001141376b0f
- http://review.source.android.com/Gerrit#change%2C8815
- http://www.ocert.org/advisories/ocert-2009-002.html
- http://www.securityfocus.com/archive/1/500750/100/0/threaded
- http://www.securityfocus.com/bid/33673
- http://android.git.kernel.org/?p=platform/external/opencore.git%3Ba=commit%3Bh=7b466cd0ecfdba72c4cbd0f3a8c2001141376b0f
- http://review.source.android.com/Gerrit#change%2C8815
- http://www.ocert.org/advisories/ocert-2009-002.html
- http://www.securityfocus.com/archive/1/500750/100/0/threaded
- http://www.securityfocus.com/bid/33673
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.