PT-2009-2652 · Gnome+1 · Gnome Rhythmbox+1

Published

2009-09-08

·

Updated

2018-10-11

·

CVE-2008-7185

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GNOME Rhythmbox version 0.11.5
Description The issue allows remote attackers to cause a denial of service, resulting in a segmentation fault and crash, by providing a playlist (.pls) file with a long Title field. This might be related to the g hash table lookup function in b-playlist-manager.c.
Recommendations For GNOME Rhythmbox version 0.11.5, consider avoiding the use of playlist files with long Title fields until a fix is available. As a temporary workaround, restrict the processing of such files to prevent the denial of service.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7185

Affected Products

Debian
Gnome Rhythmbox