~wgrant/ubuntu-cve-tracker/mainold

« back to all changes in this revision

Viewing changes to active/CVE-2007-5825

  • Committer: William Grant
  • Date: 2008-06-22 00:32:31 UTC
  • mfrom: (1065.2.136 ubuntu-cve)
  • Revision ID: william@qeuni.net-20080622003231-wungenas9mpv90zg
MergeĀ fromĀ master.

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
Candidate: CVE-2007-5825
 
2
References:
 
3
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5825
 
4
Description:
 
5
 Format string vulnerability in the ws_addarg function in webserver.c in
 
6
 mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to
 
7
 execute arbitrary code via a stats method action to /xml-rpc with format string
 
8
 specifiers in the (1) username or (2) password portion of base64-encoded data
 
9
 on the "Authorization: Basic" HTTP header line. 
 
10
Ubuntu-Description:
 
11
Notes:
 
12
Bugs:
 
13
Priority: medium
 
14
Discovered-by:
 
15
Assigned-to: 
 
16
 
 
17
Patches_mt-daapd:
 
18
upstream_mt-daapd: released (0.9~r1696-1)
 
19
dapper_mt-daapd: DNE
 
20
feisty_mt-daapd: needed
 
21
gutsy_mt-daapd: needed
 
22
hardy_mt-daapd: not-affected (0.9~r1696-1.1)
 
23
devel_mt-daapd: not-affected (0.9~r1696-1.3build1)