Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.61012
Category:Fedora Local Security Checks
Title:Fedora Core 9 FEDORA-2008-4126 (mt-daapd)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to mt-daapd
announced via advisory FEDORA-2008-4126.

The purpose of this project is built the best server software to serve
digital music to the Roku Soundbridge and iTunes
to be able to serve
the widest variety of digital music content over the widest range of
devices.

ChangeLog:

* Thu May 15 2008 W. Michael Petullo - 0.2.4.2-2
- Bump epoch.
* Wed May 14 2008 W. Michael Petullo - 0.2.4.2-1
- New upstream version.
- Remove check-input patch
it's upstream.
* Fri Apr 18 2008 W. Michael Petullo - 0.9-0.2.1696
- Apply patch by Nico Golde to fix integer overflow, Bugzilla #442688.
* Tue Feb 26 2008 W. Michael Petullo - 0.9-0.1.1696
- New upstream version.
References:

[ 1 ] Bug #442688 - CVE-2008-1771 mt-daapd: integer overflow allowing remote DoS and possibly arbitrary code execution
https://bugzilla.redhat.com/show_bug.cgi?id=442688

Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update mt-daapd' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-4126

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-1771
BugTraq ID: 28860
http://www.securityfocus.com/bid/28860
Debian Security Information: DSA-1597 (Google Search)
http://www.debian.org/security/2008/dsa-1597
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00446.html
http://www.securitytracker.com/id?1019908
http://secunia.com/advisories/29917
http://secunia.com/advisories/29919
http://secunia.com/advisories/30661
http://www.vupen.com/english/advisories/2008/1303/references
XForce ISS Database: firefly-wsgetpostvars-bo(41850)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41850
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.