| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.60785 |
| Kategorie: | Debian Local Security Checks |
| Titel: | Debian Security Advisory DSA 1538-1 (alsaplayer) |
| Zusammenfassung: | Debian Security Advisory DSA 1538-1 (alsaplayer) |
| Beschreibung: | The remote host is missing an update to alsaplayer announced via advisory DSA 1538-1. Erik Sjölund discovered a buffer overflow vulnerability in the Ogg Vorbis input plugin of the alsaplayer audio playback application. Successful exploitation of this vulnerability through the opening of a maliciously-crafted Vorbis file could lead to the execution of arbitrary code. For the stable distribution (etch), the problem has been fixed in version 0.99.76-9+etch1. For the unstable distribution (sid), the problem was fixed in version 0.99.80~ rc4-1. We recommend that you upgrade your alsaplayer packages. Solution: http://www.securityspace.com/smysecure/catid.html?in=DSA%201538-1 |
| Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2007-5301 Bugtraq: 20080409 [CVE-2007-5301] alsaplayer PoC - exploit (Google Search) http://www.securityfocus.com/archive/1/archive/1/490671/100/0/threaded http://www.milw0rm.com/exploits/5424 http://www.wekk.net/research/CVE-2007-5301/CVE-2007-5301-exploit.sh Debian Security Information: DSA-1538 (Google Search) http://www.debian.org/security/2008/dsa-1538 BugTraq ID: 25969 http://www.securityfocus.com/bid/25969 http://www.vupen.com/english/advisories/2007/3393 http://secunia.com/advisories/27117 http://secunia.com/advisories/29680 XForce ISS Database: alsaplayer-vorbis-input-bo(36996) http://xforce.iss.net/xforce/xfdb/36996 |
| Copyright | Copyright (c) 2008 E-Soft Inc. http://www.securityspace.com |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|