Alsaplayer Local Buffer Overflow Vulnerablity
BID:5767
Info
Alsaplayer Local Buffer Overflow Vulnerablity
| Bugtraq ID: | 5767 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 20 2002 12:00AM |
| Updated: | Sep 20 2002 12:00AM |
| Credit: | Discovery credited to KF of Snosoft. |
| Vulnerable: |
Alsaplayer Alsaplayer 0.99.71 |
| Not Vulnerable: | |
Discussion
Alsaplayer Local Buffer Overflow Vulnerablity
Alsaplayer is a PCM player that utilizes the ALSA libraries and drivers. It is availabe for Linux and Unix platforms.
A vulnerability has been discovered in Alsaplayer. By specifying an overly long "add-on path", it is possible for an attacker to overrun the buffer, potentially allowing for execution of attacker-supplied code.
It should be noted that although Alsaplayer is not installed setuid by default, it is common practice for users to add a setuid bit to obtain certain functionality.
Alsaplayer is a PCM player that utilizes the ALSA libraries and drivers. It is availabe for Linux and Unix platforms.
A vulnerability has been discovered in Alsaplayer. By specifying an overly long "add-on path", it is possible for an attacker to overrun the buffer, potentially allowing for execution of attacker-supplied code.
It should be noted that although Alsaplayer is not installed setuid by default, it is common practice for users to add a setuid bit to obtain certain functionality.