7.5
CVSSv2

CVE-2008-1771

Published: 16/04/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a large Content-Length.

Vulnerable Product Search on Vulmon Subscribe to Product

fireflymediaserver fireflymediaserver 0.2.4.1

Vendor Advisories

Three vulnerabilities have been discovered in the mt-daapd DAAP audio server (also known as the Firefly Media Server) The Common Vulnerabilities and Exposures project identifies the following three problems: CVE-2007-5824 Insufficient validation and bounds checking of the Authorization: HTTP header enables a heap buffer overflow, potentia ...