Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a crafted MP3 file that triggers heap corruption.
References
Configurations
History
21 Nov 2024, 00:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://android.git.kernel.org/?p=platform/external/opencore.git%3Ba=commit%3Bh=7b466cd0ecfdba72c4cbd0f3a8c2001141376b0f - | |
References | () http://review.source.android.com/Gerrit#change%2C8815 - | |
References | () http://www.ocert.org/advisories/ocert-2009-002.html - | |
References | () http://www.securityfocus.com/archive/1/500750/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/33673 - |
07 Nov 2023, 02:03
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2009-02-11 00:30
Updated : 2025-04-09 00:30
NVD link : CVE-2009-0475
Mitre link : CVE-2009-0475
CVE.ORG link : CVE-2009-0475
JSON object : View
Products Affected
android
- opencore
CWE
CWE-189
Numeric Errors