FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-1771

This CVE name corresponds to:

Entered Topic
2008-05-02 mt-daapd -- integer overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-1771
Phase Assigned(20080413)

Description

Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a large Content-Length.

References

Source Reference
CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476241
CONFIRM http://sourceforge.net/project/shownotes.php?release_id=593465&group_id=98211
DEBIAN DSA-1597
FEDORA FEDORA-2008-3250
BID 28860
VUPEN ADV-2008-1303
SECTRACK 1019908
SECUNIA 29917
SECUNIA 29919
SECUNIA 30661
XF firefly-wsgetpostvars-bo(41850)