LWN.net Logo

alsaplayer: arbitrary code execution

Package(s):alsaplayer CVE #(s):CVE-2007-5301
Created:April 7, 2008 Updated:April 9, 2008
Description:

From the Debian advisory:

Erik Sjölund discovered a buffer overflow vulnerability in the Ogg Vorbis input plugin of the alsaplayer audio playback application. Successful exploitation of this vulnerability through the opening of a maliciously-crafted Vorbis file could lead to the execution of arbitrary code.

Alerts:
Debian DSA-1538-1 2008-04-04

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.