[PLSN-0007] new libcdaudio package available

From: Peachtree Linux Security Team (security_at_peachtree.burdell.org)
Date: 04/26/05

  • Next message: Peachtree Linux Security Team: "[PLSN-0006] new libexif package available"
    Date: Mon, 25 Apr 2005 22:14:11 -0400
    To: peachlnx-security@lists.sourceforge.net, bugtraq@securityfocus.com
    
    
    

    ---------------------------------------------------------------------------
    Peachtree Linux Security Notice PLSN-0007
    April 22, 2005

    Remote DoS and possible code execution in libcdaudio
    CAN-2005-0706
    ---------------------------------------------------------------------------

    The following Peachtree Linux releases are affected:

       Peachtree Linux release 1 ("Atlanta")

    Description:

       CAN-2005-0706: Buffer overflow in CDDB result handling allows
       attackers to cause a denial of service (crash) and possible execute
       arbitrary code by causing the cddb lookup to return more matches than
       expected.

       (NOTE: This vulnerability was originally found to affect grip. We do
       not ship grip, but Mandriva found that the vulnerability affected
       libcdaudio and gnome-vfs.)

    Packages:

       alpha
          7087c543031ed7c2799b047b4d8b2c24 libcdaudio-0.99.4.alpha.dist

       i386
          ca2ca9a7677148641f5c598be1d330b1 libcdaudio-0.99.4.i686.dist

       ppc
          f22c18b50e37e31437ba3ad44fc09d1e libcdaudio-0.99.4.ppc.dist

    Solution:

       Download the appropriate package for your release of Peachtree linux.
       Upgrade your system to the new package:

          distadd -u packagename

       Where package name is the name of the package file from the list above.

    -- 
    Peachtree Linux Security Team
    http://peachtree.burdell.org/
    
    



  • Next message: Peachtree Linux Security Team: "[PLSN-0006] new libexif package available"

    Relevant Pages

    • [PLSN-0001] - Multiple PHP vulnerabilities
      ... Peachtree Linux Security Notice PLSN-0001 ... Remote code execution and remote DoS vulnerability in PHP ... Download the appropriate package for your release of Peachtree Linux. ...
      (Bugtraq)
    • [PLSN-0001] - Multiple vulnerabilities in Gaim
      ... Peachtree Linux Security Notice PLSN-0001 ... Remote code execution and remote DoS vulnerability in PHP ... Download the appropriate package for your release of Peachtree Linux. ...
      (Bugtraq)
    • [PLSN-0004] - Buffer overflow in PostgreSQL
      ... Peachtree Linux Security Notice PLSN-0004 ... Buffer overflow in PL/PGSQL parser allowing database users to run arbitrary ... to run SQL statements to execute arbitrary code as the pgsql user. ... Download the appropriate package for your release of Peachtree linux. ...
      (Bugtraq)
    • [PLSN-0003] - Remote exploits in MPlayer
      ... Peachtree Linux Security Notice PLSN-0003 ... A buffer overflow vulnerability exists in the RTSP stream module, ... which could allow malicious servers of MMS or TCP streams to execute ... Download the appropriate package for your release of Peachtree Linux. ...
      (Bugtraq)
    • [PLSN-0003] - Remote exploits in mplayer
      ... Peachtree Linux Security Notice PLSN-0003 ... A buffer overflow vulnerability exists in the RTSP stream module, ... which could allow malicious servers of MMS or TCP streams to execute ... Download the appropriate package for your release of Peachtree Linux. ...
      (Bugtraq)