Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
BID:17372
Info
Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
| Bugtraq ID: | 17372 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-0051 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2006 12:00AM |
| Updated: | Jun 27 2006 03:20AM |
| Credit: | Discovery of this issue is credited to Marcus Meissner. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Kaffeine Media Player 0.7.1 Kaffeine Media Player 0.5 rc1 Kaffeine Media Player 0.4.3 b Kaffeine Media Player 0.4.3 Kaffeine Media Player 0.4.2 Kaffeine Media Player 0.7 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Kaffeine Media Player 0.8 |
Discussion
Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
Kaffiene is reportedly affected by a remote buffer-overflow vulnerability because the application fails to perform sufficient boundary checks on user-supplied strings before copying them into finite stack-based buffers.
An attacker can leverage this issue remotely to execute arbitrary code on an affected computer with the privileges of an unsuspecting user that executed the vulnerable software.
Kaffiene is reportedly affected by a remote buffer-overflow vulnerability because the application fails to perform sufficient boundary checks on user-supplied strings before copying them into finite stack-based buffers.
An attacker can leverage this issue remotely to execute arbitrary code on an affected computer with the privileges of an unsuspecting user that executed the vulnerable software.
Exploit / POC
Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
Solution:
The vendor has released a security advisory along with an updated version of Kaffeine and patches to address this issue.
Please see the referenced advisories for more information.
Kaffeine Media Player 0.7
Kaffeine Media Player 0.4.2
Kaffeine Media Player 0.4.3 b
Kaffeine Media Player 0.4.3
Kaffeine Media Player 0.5 rc1
Kaffeine Media Player 0.7.1
Solution:
The vendor has released a security advisory along with an updated version of Kaffeine and patches to address this issue.
Please see the referenced advisories for more information.
Kaffeine Media Player 0.7
-
Mandriva kaffeine-0.7-6.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva kaffeine-0.7-6.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva lib64kaffeine0-0.7-6.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva lib64kaffeine0-devel-0.7-6.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libkaffeine0-0.7-6.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libkaffeine0-devel-0.7-6.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/
Kaffeine Media Player 0.4.2
-
Kaffeine kaffeine-0.8.1.tar.bz2
http://prdownloads.sourceforge.net/kaffeine/kaffeine-0.8.1.tar.bz2?dow nload -
KDE kaffeine-0.4.x-CVE-2006-0051.patch
ftp://ftp.kde.org/pub/kde/security_patches/kaffeine-0.4.x-CVE-2006-005 1.patch
Kaffeine Media Player 0.4.3 b
-
Kaffeine kaffeine-0.8.1.tar.bz2
http://prdownloads.sourceforge.net/kaffeine/kaffeine-0.8.1.tar.bz2?dow nload -
KDE kaffeine-0.4.x-CVE-2006-0051.patch
ftp://ftp.kde.org/pub/kde/security_patches/kaffeine-0.4.x-CVE-2006-005 1.patch
Kaffeine Media Player 0.4.3
-
Kaffeine kaffeine-0.8.1.tar.bz2
http://prdownloads.sourceforge.net/kaffeine/kaffeine-0.8.1.tar.bz2?dow nload -
KDE kaffeine-0.4.x-CVE-2006-0051.patch
ftp://ftp.kde.org/pub/kde/security_patches/kaffeine-0.4.x-CVE-2006-005 1.patch
Kaffeine Media Player 0.5 rc1
-
Kaffeine kaffeine-0.8.1.tar.bz2
http://prdownloads.sourceforge.net/kaffeine/kaffeine-0.8.1.tar.bz2?dow nload -
KDE kaffeine-0.5.x-CVE-2006-0051.patch
ftp://ftp.kde.org/pub/kde/security_patches/kaffeine-0.5.x-CVE-2006-005 1.patch
Kaffeine Media Player 0.7.1
-
Kaffeine kaffeine-0.8.1.tar.bz2
http://prdownloads.sourceforge.net/kaffeine/kaffeine-0.8.1.tar.bz2?dow nload -
KDE kaffeine-0.7.x-CVE-2006-0051.patch
ftp://ftp.kde.org/pub/kde/security_patches/kaffeine-0.7.x-CVE-2006-005 1.patch
References
Kaffeine Remote HTTP_Peek Buffer Overflow Vulnerability
References:
References:
- Kaffeine buffer overflow (KDE)
- Kaffeine Media Player Home Page (Kaffeine)