PT-2008-1727 · Nullsoft+1 · Winamp Remote+1
Published
2008-03-31
·
Updated
2017-08-08
·
CVE-2008-0070
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Orb Networks Orb version 2.00.1014
Winamp Remote BETA
Description
The issue is related to an integer overflow that can be triggered by a remote attacker via an RPC request. This request specifies a large number of array dimensions, leading to a heap-based buffer overflow, which allows the execution of arbitrary code.
Recommendations
For Orb Networks Orb version 2.00.1014, update to a version that fixes the integer overflow issue.
For Winamp Remote BETA, avoid using the RPC request functionality until a patch is available that addresses the heap-based buffer overflow.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Orb
Winamp Remote