← Vulnerability feed

Vulnerability record · CVE-2009-1438 · published 27 April 2009

CVE-2009-1438: Konstanty bialkowski libmodplug vulnerability

KKonstanty Bialkowski · Libmodplug

Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based buffer overflow, as exploited in the wild in August 2008.

7.5 CVSS 2.0 High EPSS 4.7% · top 8.6% CWE-189 · CWE-189
7.5CVSS 2.0 base score
4.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
48References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based buffer overflow, as exploited in the wild in August 2008.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.gentoo.org/show_bug.cgi?id=266913
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
http://modplug-xmms.cvs.sourceforge.net/viewvc/modplug-xmms/libmodplug/src/load_med.cpp?r1=1.1&amp%3Br2=1.2
http://osvdb.org/53801 Patch
http://secunia.com/advisories/34797 Vendor Advisory
http://secunia.com/advisories/34930
http://secunia.com/advisories/35026
http://secunia.com/advisories/35685
http://secunia.com/advisories/35736
http://secunia.com/advisories/36158
http://secunia.com/advisories/36183
http://security.gentoo.org/glsa/glsa-200907-07.xml
http://sourceforge.net/project/shownotes.php?release_id=677065&group_id=1275 Patch
http://www.debian.org/security/2009/dsa-1850
http://www.debian.org/security/2009/dsa-1851
http://www.mandriva.com/security/advisories?name=MDVSA-2009:128
http://www.openwall.com/lists/oss-security/2009/04/21/4
http://www.redhat.com/archives/fedora-package-announce/2009-April/msg00907.html
http://www.redhat.com/archives/fedora-package-announce/2009-April/msg00908.html
http://www.securityfocus.com/bid/30801 ExploitPatch
http://www.ubuntu.com/usn/USN-771-1
http://www.vupen.com/english/advisories/2009/1104 PatchVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=496834
https://exchange.xforce.ibmcloud.com/vulnerabilities/50388
http://bugs.gentoo.org/show_bug.cgi?id=266913
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
http://modplug-xmms.cvs.sourceforge.net/viewvc/modplug-xmms/libmodplug/src/load_med.cpp?r1=1.1&amp%3Br2=1.2
http://osvdb.org/53801 Patch
http://secunia.com/advisories/34797 Vendor Advisory
http://secunia.com/advisories/34930
http://secunia.com/advisories/35026
http://secunia.com/advisories/35685
http://secunia.com/advisories/35736
http://secunia.com/advisories/36158
http://secunia.com/advisories/36183
http://security.gentoo.org/glsa/glsa-200907-07.xml
http://sourceforge.net/project/shownotes.php?release_id=677065&group_id=1275 Patch
http://www.debian.org/security/2009/dsa-1850
http://www.debian.org/security/2009/dsa-1851
http://www.mandriva.com/security/advisories?name=MDVSA-2009:128

Track CVE-2009-1438 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2013-4234Konstanty bialkowski libmodplug memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier all…EPSS 4.4%6.8CVE-2013-4233Konstanty bialkowski libmodplug vulnerabilityInteger overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service…EPSS 4.1%6.8CVE-2011-2911Konstanty bialkowski libmodplug vulnerabilityInteger overflow in the CSoundFile::ReadWav function in src/load_wav.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of se…EPSS 4.3%6.8CVE-2011-2912Konstanty bialkowski libmodplug memory buffer overflow vulnerabilityStack-based buffer overflow in the CSoundFile::ReadS3M function in src/load_s3m.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a d…EPSS 4.3%6.8CVE-2011-2913Konstanty bialkowski libmodplug vulnerabilityOff-by-one error in the CSoundFile::ReadAMS function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of se…EPSS 4.6%6.8CVE-2011-2914Konstanty bialkowski libmodplug vulnerabilityOff-by-one error in the CSoundFile::ReadDSM function in src/load_dms.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of se…EPSS 4.6%6.8CVE-2011-2915Konstanty bialkowski libmodplug vulnerabilityOff-by-one error in the CSoundFile::ReadAMS2 function in src/load_ams.cpp in libmodplug before 0.8.8.4 allows remote attackers to cause a denial of s…EPSS 4.2%6.8CVE-2011-1761Konstanty bialkowski libmodplug memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in the (1) abc_new_macro and (2) abc_new_umacro functions in src/load_abc.cpp in libmodplug before 0.8.8.3 allo…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2009-1438), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.