Family: Gentoo Local Security Checks --> Category: infos
[GLSA-200604-04] Kaffeine: Buffer overflow Vulnerability Scan
Vulnerability Scan Summary
Kaffeine: Buffer overflow
Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200604-04
(Kaffeine: Buffer overflow)
Kaffeine uses an unchecked buffer when fetching remote RAM
playlists via HTTP.
A remote attacker could entice a user to play a specially-crafted
RAM playlist resulting in the execution of arbitrary code with the
permissions of the user running the application.
There is no known workaround at this time.
All Kaffeine users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-video/kaffeine-0.7.1-r2"
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.