← back
CVE-2009-1391observed exploitation

CVE-2009-1391

45Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 7.4%
from disclosure to weapon0 days
Published on NVDJun 16
1st PoCMay 11
VulnCheckJun 16
exploitation probability
7.4%top 6% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild by Trojan.Downloader-71014 in June 2009.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.