|
|
| |
|
| |
Kaffeine, gxine: remotely exploitable buffer overflow
| Package(s): | Kaffeine gxine |
CVE #(s): | |
| Created: | November 8, 2004 |
Updated: | November 11, 2004 |
| Description: |
KF of Secure Network Operations has discovered an overflow that occurs
during the Content-Type header processing of Kaffeine. The vulnerable code
in Kaffeine is reused from gxine, making gxine vulnerable as well. An
attacker could create a specially-crafted Content-type header from a
malicious HTTP server, and crash a user's instance of Kaffeine or gxine,
potentially allowing the execution of arbitrary code. See this SecurityTracker
advisory for details. |
| Alerts: |
|
( Log in to post comments)
|
|
|