10
CVSSv2

CVE-2008-5030

Published: 10/11/2008 Updated: 08/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the cddb_read_disc_data function in cddb.c in libcdaudio 0.99.12p2 allows remote CDDB servers to execute arbitrary code via long CDDB data.

Vulnerable Product Search on Vulmon Subscribe to Product

libcaudio libcaudio 0.99.12p2

Vendor Advisories

Debian Bug report logs - #505478 CVE-2008-5030: Buffer overflow Package: libcdaudio; Maintainer for libcdaudio is Debian QA Group <packages@qadebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 12 Nov 2008 21:21:01 UTC Severity: grave Tags: security Fixed in version libcdaudio/09912p2-7 Done ...
It was discovered that a heap overflow in the CDDB retrieval code of libcdaudio, a library for controlling a CD-ROM when playing audio CDs, may result in the execution of arbitrary code For the stable distribution (etch), this problem has been fixed in version 09912p2-2+etch1 A package for hppa will be provided later For the upcoming stable di ...