LWN.net Logo

audacity: buffer overflow

Package(s):audacity CVE #(s):CVE-2009-0490
Created:February 26, 2009 Updated:March 9, 2009
Description: Audacity has a buffer overflow vulnerability. From the Mandriva alert: Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string.
Alerts:
Gentoo 200903-03 2009-03-06
Mandriva MDVSA-2009:055 2009-02-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds