CVE-2009-0490

Audacity <1.3.6 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Houssamix · perldoswindows
https://www.exploit-db.com/exploits/7634
exploitdb WORKING POC VERIFIED
by Encrypt3d.M!nd · pythonlocalwindows
https://www.exploit-db.com/exploits/10322
exploitdb WORKING POC VERIFIED
by mr_me · pythonlocalwindows
https://www.exploit-db.com/exploits/9501

Scores

EPSS 0.5806
EPSS Percentile 98.2%

Classification

CWE
CWE-787
Status draft

Affected Products (1)

audacityteam/audacity < 1.3.6

Timeline

Published Feb 10, 2009
Tracked Since Feb 18, 2026