Firefly Media Server 'Content-Length' Buffer Overflow Vulnerability
BID:28860
Info
Firefly Media Server 'Content-Length' Buffer Overflow Vulnerability
| Bugtraq ID: | 28860 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1771 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2008 12:00AM |
| Updated: | May 07 2015 05:09PM |
| Credit: | Nico Golde, Debian security team |
| Vulnerable: |
Fireflymediaserver Firefly Media Server 0.2.4 1 Fireflymediaserver Firefly Media Server 0.2.4 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Fireflymediaserver Firefly Media Server 0.2.4 .2 |
Discussion
Firefly Media Server 'Content-Length' Buffer Overflow Vulnerability
Firefly Media Server (formerly known as mt-daapd) is prone to a buffer-overflow vulnerability because it fails to perform adequate checks on user-supplied input.
Exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application. Failed attacks will likely cause denial-of-service conditions.
Versions prior to Firefly Media Server 0.2.4.2 are affected.
Firefly Media Server (formerly known as mt-daapd) is prone to a buffer-overflow vulnerability because it fails to perform adequate checks on user-supplied input.
Exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application. Failed attacks will likely cause denial-of-service conditions.
Versions prior to Firefly Media Server 0.2.4.2 are affected.
Exploit / POC
Firefly Media Server 'Content-Length' Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Firefly Media Server 'Content-Length' Buffer Overflow Vulnerability
Solution:
Vendor advisories are available. Please see the references for more information.
Solution:
Vendor advisories are available. Please see the references for more information.
References
Firefly Media Server 'Content-Length' Buffer Overflow Vulnerability
References:
References:
- Firefly Media Server Homepage (Firefly Media Server)
- Release Notes (Firefly Media Server)