header-logo
Suggest Exploit
vendor:
AlsaPlayer
by:
Unknown
7.5
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: AlsaPlayer
Affected Version From: Prior to AlsaPlayer 0.99.80-rc3
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:alsaplayer_project:alsaplayer
Metasploit:
Other Scripts:
Platforms Tested:
Unknown

Remote Buffer Overflow Vulnerability in AlsaPlayer

AlsaPlayer is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized buffer. Exploiting this issue allows attackers to execute arbitrary machine code in the context of users running the affected application.

Mitigation:

Upgrade to AlsaPlayer version 0.99.80-rc3 or later.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/25969/info

AlsaPlayer is prone to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it to an insufficiently sized buffer.

Exploiting this issue allows attackers to execute arbitrary machine code in the context of users running the affected application.

This issue affects versions prior to AlsaPlayer 0.99.80-rc3. 

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30648.ogg