CVE Database
/

CVE-2006-4089

Back to search

CVE-2006-4089

Published: Aug 11, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of service (application crash), or have other unknown impact, via (1) a long Location field sent by a web server, which triggers an overflow in the reconnect function in reader/http/http.c; (2) a long URL sent by a web server when AlsaPlayer is seeking a media file for the playlist, which triggers overflows in new_list_item and CbUpdated in interface/gtk/PlaylistWindow.cpp; and (3) a long response sent by a CDDB server, which triggers an overflow in cddb_lookup in input/ccda/cdda_engine.c.

VendorProductVersions

n/a

n/a

affected
n/a

References

19450
vdb-entry
x_refsource_BID
27883
vdb-entry
x_refsource_OSVDB
1356
third-party-advisory
x_refsource_SREASON
27885
vdb-entry
x_refsource_OSVDB
27884
vdb-entry
x_refsource_OSVDB
21749
third-party-advisory
x_refsource_SECUNIA
alsaplayer-reconnect-bo(28306)
vdb-entry
x_refsource_XF
22018
third-party-advisory
x_refsource_SECUNIA
21422
third-party-advisory
x_refsource_SECUNIA
GLSA-200608-24
vendor-advisory
x_refsource_GENTOO
SUSE-SR:2006:021
vendor-advisory
x_refsource_SUSE
DSA-1179
vendor-advisory
x_refsource_DEBIAN
alsaplayer-cddblookup-bo(28308)
vdb-entry
x_refsource_XF
alsaplayer-gtkplaylist-bo(28307)
vdb-entry
x_refsource_XF
ADV-2006-3235
vdb-entry
x_refsource_VUPEN
21639
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now