vendor:
AlsaPlayer
by:
Unknown
7.5
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: AlsaPlayer
Affected Version From: Prior to AlsaPlayer 0.99.80-rc3
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:alsaplayer_project:alsaplayer
Platforms Tested:
Unknown
Remote Buffer Overflow Vulnerability in AlsaPlayer
AlsaPlayer is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized buffer. Exploiting this issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
Mitigation:
Upgrade to AlsaPlayer version 0.99.80-rc3 or later.