Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Gentoo Local Security Checks --> Category: infos

[GLSA-200607-13] Audacious: Multiple heap and buffer overflows Vulnerability Scan


Vulnerability Scan Summary
Audacious: Multiple heap and buffer overflows

Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200607-13
(Audacious: Multiple heap and buffer overflows)


Luigi Auriemma has found that the adplug library fails to verify the
size of the destination buffers in the unpacking instructions,
resulting in various possible heap and buffer overflows.

Impact

A possible hacker can entice a user to load a specially crafted media file,
resulting in a crash or possible execution of arbitrary code.

Workaround

There is no known workaround at this time.

References:
http://www.securityfocus.com/archive/1/439432/30/0/threaded
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3581
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3582


Solution:
All Audacious users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-sound/audacious-1.1.0"


Threat Level: Medium


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.