Kaffeine Remote Buffer Overflow Vulnerability
BID:11528
Info
Kaffeine Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11528 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2004 12:00AM |
| Updated: | Oct 26 2004 12:00AM |
| Credit: | Discovery of this issue is credited to KF <[email protected]>. |
| Vulnerable: |
Kaffeine Media Player 0.5 rc1 Kaffeine Media Player 0.4.3 b Kaffeine Media Player 0.4.3 Kaffeine Media Player 0.4.2 gxine gxine 0.3 Gentoo Linux |
| Not Vulnerable: |
gxine gxine 0.3.3 -r1 |
Discussion
Kaffeine Remote Buffer Overflow Vulnerability
Kaffiene is reportedly affected by a remote buffer overflow vulnerability. The problem presents itself due to insufficient boundary checks on user-supplied strings prior to copying them into finite stack-based buffers.
An attacker can leverage this issue remotely to execute arbitrary code on an affected computer with the privileges of an unsuspecting user that executed the vulnerable software.
Kaffiene is reportedly affected by a remote buffer overflow vulnerability. The problem presents itself due to insufficient boundary checks on user-supplied strings prior to copying them into finite stack-based buffers.
An attacker can leverage this issue remotely to execute arbitrary code on an affected computer with the privileges of an unsuspecting user that executed the vulnerable software.
Exploit / POC
Kaffeine Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Kaffeine Remote Buffer Overflow Vulnerability
Solution:
Gentoo Linux has released advisory GLSA 200411-14:01 to address this issue in Kaffeine and gxine. Users of the affected packages are urged to execute the following commands with superuser privileges to install the updates:
For Kaffeine:
emerge --sync
emerge --ask --oneshot --verbose ">=media-video/kaffeine-0.4.3b-r1"
For gxine:
emerge --sync
emerge --ask --oneshot --verbose ">=media-video/gxine-0.3.3-r1"
Solution:
Gentoo Linux has released advisory GLSA 200411-14:01 to address this issue in Kaffeine and gxine. Users of the affected packages are urged to execute the following commands with superuser privileges to install the updates:
For Kaffeine:
emerge --sync
emerge --ask --oneshot --verbose ">=media-video/kaffeine-0.4.3b-r1"
For gxine:
emerge --sync
emerge --ask --oneshot --verbose ">=media-video/gxine-0.3.3-r1"
References
Kaffeine Remote Buffer Overflow Vulnerability
References:
References:
- Kaffeine Media Player Home Page (Kaffeine)