Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 9 2008-11956 Moderate: libcdaudio Buffer Overflow Threat

fedora
Calendar Grey February 4, 2009
Dist Fedora Esm H88
A patch addresses a heap-based overflow flaw in libcdaudio version 0.99.12p2 for Fedora 9 systems.
This update fixes a potential buffer overflow caused by large amount of CDDB replies (CVE-2005-0706).

Summary

libcdaudio is a library designed to provide functions to control

operation of a CD-ROM when playing audio CDs. It also contains

functions for CDDB and CD Index lookup.

This update fixes a potential buffer overflow caused by large amount of CDDB

replies (CVE-2005-0706).

* Sat Dec 27 2008 Axel Thimm - 0.99.12p2-11

- Fix CVE-2005-0706.

* Wed May 21 2008 Tom "spot" Callaway - 0.99.12p2-10

- took COPYING out of doc (it is simply wrong)

- fixed license tag

[ 1 ] Bug #470552 - CVE-2005-0706 grip,libcdaudio: buffer overflow caused by large amount of CDDB replies

https://bugzilla.redhat.com/show_bug.cgi?id=470552

su -c 'yum update libcdaudio' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 9
Version: 0.99.12p2
Release: 11.fc9
URL:
Summary: Control operation of a CD-ROM when playing audio CDs

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here