Gentoo Linux Security Advisory GLSA 200608-24
https://security.gentoo.org/
Severity: Normal
Title: AlsaPlayer: Multiple buffer overflows
Date: August 26, 2006
Bugs: #143402
ID: 200608-24
Synopsis
=======
AlsaPlayer is vulnerable to multiple buffer overflows which could lead
to the execution of arbitrary code.
Background
=========
AlsaPlayer is a heavily multithreaded PCM player that tries to utilize
ALSA utilities and drivers. As of June 2004, the project is inactive.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 media-sound/alsaplayer <= 0.99.76-r3 Vulnerable!
-------------------------------------------------------------------
NOTE: Certain packages are still vulnerable. Users should migrate
to another package if one is available or wait for the
existing packages to be marked stable by their
architecture maintainers.
==========
AlsaPlayer contains three buffer overflows: in the function that
handles the HTTP connections, the GTK interface, and the CDDB queryi...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.