~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2006-4089

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDate: 2006-08-11
2
 
Candidate: CVE-2006-4089
3
 
References: 
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4089
5
 
Description:
6
 
 Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier
7
 
 allow remote attackers to cause a denial of service (application crash), or
8
 
 have other unknown impact, via (1) a long Location field sent by a web
9
 
 server, which triggers an overflow in the reconnect function in
10
 
 reader/http/http.c; (2) a long URL sent by a web server when AlsaPlayer is
11
 
 seeking a media file for the playlist, which triggers overflows in
12
 
 new_list_item and CbUpdated in interface/gtk/PlaylistWindow.cpp; and (3) a
13
 
 long response sent by a CDDB server, which triggers an overflow in
14
 
 cddb_lookup in input/ccda/cdda_engine.c.
15
 
Ubuntu-Description: 
16
 
Notes: 
17
 
Bugs: 
18
 
#sid_PKG:
19
 
#dapper_PKG:
20
 
#edgy_PKG:
21
 
#feisty_PKG:
22
 
#devel_PKG:
23
 
dapper_alsaplayer: ignored (reached end-of-life)
24
 
edgy_alsaplayer: needed (reached end-of-life)
25
 
feisty_alsaplayer: released (0.99.76-9)
26
 
gutsy_alsaplayer: released (0.99.76-9)
27
 
hardy_alsaplayer: released (0.99.76-9)
28
 
intrepid_alsaplayer: released (0.99.76-9)
29
 
jaunty_alsaplayer: released (0.99.76-9)
30
 
karmic_alsaplayer: released (0.99.76-9)
31
 
devel_alsaplayer: released (0.99.76-9)
32
 
upstream_alsaplayer: