Описание
Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:kaffeine:kaffeine_player:0.4.2:*:*:*:*:*:*:*
cpe:2.3:a:kaffeine:kaffeine_player:0.4.3:*:*:*:*:*:*:*
cpe:2.3:a:kaffeine:kaffeine_player:0.4.3b:*:*:*:*:*:*:*
cpe:2.3:a:kaffeine:kaffeine_player:0.5_rc1:*:*:*:*:*:*:*
cpe:2.3:a:xine:gxine:0.3:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.0593
Низкий
10 Critical
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
debian
больше 20 лет назад
Buffer overflow in the http_open function in Kaffeine before 0.5, whos ...
github
больше 3 лет назад
Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.
EPSS
Процентиль: 90%
0.0593
Низкий
10 Critical
CVSS2
Дефекты
NVD-CWE-Other