LWN.net Logo

libcdio: arbitrary code execution

Package(s):libcdio CVE #(s):CVE-2007-6613
Created:January 21, 2008 Updated:March 7, 2008
Description:

From the Gentoo advisory:

Devon Miller reported a boundary error in the "print_iso9660_recurse()" function in files cd-info.c and iso-info.c when processing long filenames within Joliet images.

A remote attacker could entice a user to open a specially crafted ISO image in the cd-info and iso-info applications, resulting in the execution of arbitrary code with the privileges of the user running the application. Applications linking against shared libraries of libcdio are not affected.

Alerts:
Ubuntu USN-580-1 2008-02-20
SuSE SUSE-SR:2008:005 2008-03-06
Mandriva MDVSA-2008:037 2007-02-07
Gentoo 200801-08 2008-01-20

(Log in to post comments)

libcdio: arbitrary code execution

Posted Feb 7, 2008 17:58 UTC (Thu) by kreutzm (subscriber, #4700) [Link]

Debian Sarge and Etch are not vulnerable.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds