LWN.net Logo

Streamripper: multiple vulnerabilities

Package(s):streamripper CVE #(s):CVE-2008-4829
Created:January 12, 2009 Updated:January 14, 2009
Description:

From the Gentoo advisory:

Stefan Cornelius from Secunia Research reported multiple buffer overflows in the http_parse_sc_header(), http_get_pls() and http_get_m3u() functions in lib/http.c when parsing overly long HTTP headers, or pls and m3u playlists with overly long entries.

A remote attacker could entice a user to connect to a malicious server, possibly resulting in the remote execution of arbitrary code with the privileges of the user running the application.

Alerts:
Gentoo 200901-05 2009-01-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds