Browse Source

Updated alsaplayer (0.99.76 -> 0.99.80) : SECURITY - MEDIUM

CVE-2006-4089 (Medium) :
Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers
to cause a denial of service (application crash), or have other unknown impact, via (1) a long
Location field sent by a web server, which triggers an overflow in the reconnect function in
reader/http/http.c; (2) a long URL sent by a web server when AlsaPlayer is seeking a media file
for the playlist, which triggers overflows in new_list_item and CbUpdated in
interface/gtk/PlaylistWindow.cpp; and (3) a long response sent by a CDDB server, which triggers
an overflow in cddb_lookup in input/ccda/cdda_engine.c.

CVE-2007-5301 (Medium) :
Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis
input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code
via a .OGG file with long comments.
early
Aldas Nabazas 17 years ago
parent
commit
6e9dcbd6a7
  1. 6
      audio/alsaplayer/alsaplayer.desc

6
audio/alsaplayer/alsaplayer.desc

@ -3,7 +3,7 @@
[COPY] This copyright note is auto-generated by ./scripts/Create-CopyPatch.
[COPY]
[COPY] Filename: package/.../alsaplayer/alsaplayer.desc
[COPY] Copyright (C) 2006 The OpenSDE Project
[COPY] Copyright (C) 2006 - 2008 The OpenSDE Project
[COPY] Copyright (C) 2004 - 2006 The T2 SDE Project
[COPY] Copyright (C) 1998 - 2004 Clifford Wolf
[COPY]
@ -33,8 +33,8 @@
[L] GPL
[S] Stable
[V] 0.99.76
[V] 0.99.80
[P] X -----5---9 146.500
[D] 143976927 alsaplayer-0.99.76.tar.bz2 ftp://ftp.alsa-project.org/pub/people/andy/
[D] 2322619381 alsaplayer-0.99.80.tar.bz2 http://www.alsaplayer.org/

Loading…
Cancel
Save