Sploitus

CVE-2009-2206

No indexed exploits for CVE-2009-2206 yet

Multiple heap-based buffer overflows in the AudioCodecs library in the CoreAudio component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted (1) AAC or (2) MP3 file, as demonstrated by a ringtone with malformed entries in the sample size table.

Affected products
Audiocodecs, Coreaudio, Ios, Ipod Touch
Apple Iphone Os
All versions
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
4.6% (91th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2009-09-10
CVE-2009-2206 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2009-2206 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2009-2206 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.