5.1
CVSSv2

CVE-2006-0051

Published: 05/04/2006 Updated: 19/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in playlistimport.cpp in Kaffeine Player 0.4.2 up to and including 0.7.1 allows user-assisted malicious users to execute arbitrary code via long HTTP request headers when Kaffeine is "fetching remote playlists", which triggers the overflow in the http_peek function.

Vulnerable Product Search on Vulmon Subscribe to Product

kaffeine kaffeine player 0.4.2

kaffeine kaffeine player 0.4.3

kaffeine kaffeine player 0.4.3b

kaffeine kaffeine player 0.5_rc1

kaffeine kaffeine player 0.7.1

Vendor Advisories

Marcus Meissner discovered a buffer overflow in the http_peek() function By tricking an user into opening a specially crafted playlist URL with Kaffeine, a remote attacker could exploit this to execute arbitrary code with the user’s privileges ...
Marcus Meissner discovered that kaffeine, a versatile media player for KDE 3, contains an unchecked buffer that can be overwritten remotely when fetching remote RAM playlists which can cause the execution of arbitrary code The old stable distribution (woody) does not contain kaffeine packages For the stable distribution (sarge) this problem has b ...