FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-0051

This CVE name corresponds to:

Entered Topic
2006-04-07 kaffeine -- buffer overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-0051
Phase Assigned(20051228)

Description

Buffer overflow in playlistimport.cpp in Kaffeine Player 0.4.2 through 0.7.1 allows user-assisted attackers to execute arbitrary code via long HTTP request headers when Kaffeine is "fetching remote playlists", which triggers the overflow in the http_peek function.

References

Source Reference
BUGTRAQ 20060405 [Kaffeine Security Advisory] Heap based buffer overflow in http_peek()
CONFIRM http://www.kde.org/info/security/advisory-20060404-1.txt
DEBIAN DSA-1023
GENTOO GLSA-200604-04
MANDRIVA MDKSA-2006:065
SUSE SUSE-SR:2006:008
UBUNTU USN-268-1
BID 17372
VUPEN ADV-2006-1229
SECTRACK 1015863
SECUNIA 19525
SECUNIA 19540
SECUNIA 19542
SECUNIA 19549
SECUNIA 19557
SECUNIA 19571
XF kaffeine-http-peek-bo(25631)