FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-4089

This CVE name corresponds to:

Entered Topic
2006-08-13 alsaplayer -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-4089
Phase Assigned(20060810)

Description

Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of service (application crash), or have other unknown impact, via (1) a long Location field sent by a web server, which triggers an overflow in the reconnect function in reader/http/http.c; (2) a long URL sent by a web server when AlsaPlayer is seeking a media file for the playlist, which triggers overflows in new_list_item and CbUpdated in interface/gtk/PlaylistWindow.cpp; and (3) a long response sent by a CDDB server, which triggers an overflow in cddb_lookup in input/ccda/cdda_engine.c.

References

Source Reference
BUGTRAQ 20060809 Multiple buffer-overflows in AlsaPlayer 0.99.76
FULLDISC 20060809 Multiple buffer-overflows in AlsaPlayer 0.99.76
MISC http://aluigi.altervista.org/adv/alsapbof-adv.txt
DEBIAN DSA-1179
GENTOO GLSA-200608-24
SUSE SUSE-SR:2006:021
BID 19450
VUPEN ADV-2006-3235
OSVDB 27883
OSVDB 27884
OSVDB 27885
SECUNIA 21422
SECUNIA 21639
SECUNIA 22018
SECUNIA 21749
SREASON 1356
XF alsaplayer-cddblookup-bo(28308)
XF alsaplayer-gtkplaylist-bo(28307)
XF alsaplayer-reconnect-bo(28306)