FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0706

This CVE name corresponds to:

Entered Topic
2009-01-11 libcdaudio -- remote buffer overflow and code execution
2005-03-14 grip -- CDDB response multiple matches buffer overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0706
Phase Assigned(20050309)

Description

Buffer overflow in discdb.c for grip 3.1.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the cddb lookup to return more matches than expected.

References

Source Reference
MISC http://sourceforge.net/tracker/index.php?func=detail&aid=834724&group_id=3714&atid=103714
CONFIRM http://sourceforge.net/tracker/index.php?func=detail&aid=1160134&group_id=3714&atid=303714
CONFIRM http://rpmfind.net/linux/RPM/suse/9.3/i386/suse/i586/gnome-vfs-1.0.5-816.2.i586.html
FEDORA FLSA:152919
FEDORA FEDORA-2008-11956
FEDORA FEDORA-2008-9521
FEDORA FEDORA-2008-9604
GENTOO GLSA-200503-21
REDHAT RHSA-2005:304
REDHAT RHSA-2009:0005
BID 12770
OVAL oval:org.mitre.oval:def:10768
SECUNIA 33389
SECUNIA 33824
SECUNIA 32803
XF grip-cddb-bo(19648)