PT-2007-6374 · Alsa · Alsaplayer

Whats

·

Published

2007-10-09

·

Updated

2018-10-15

·

CVE-2007-5301

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: AlsaPlayer versions prior to 0.99.80-rc3
Description: The issue is related to a buffer overflow in the vorbis stream info function, which can be triggered by a .OGG file containing long comments. This allows remote attackers to execute arbitrary code.
Recommendations: For versions prior to 0.99.80-rc3, update to version 0.99.80-rc3 or later to resolve the issue. As a temporary workaround, consider avoiding the use of .OGG files with long comments until the update is applied.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5301
DSA-1538-1
DTSA-66-1

Affected Products

Alsaplayer