The remote host is missing updates announced in
advisory GLSA 200607-13.
The adplug library included in Audacious is vulnerable to various overflows
that could result in the execution of arbitrary code.
Solution:
All Audacious users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=media-sound/audacious-1.1.0'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200607-13
http://bugs.gentoo.org/show_bug.cgi?id=139957
http://www.securityfocus.com/archive/1/439432/30/0/threaded
Risk factor : Medium
Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-3581
Bugtraq: 20060706 Various heap and stack overflow bugs in AdPlug library 2.0 (CVS 04 Jul 2006) (Google Search)
http://www.securityfocus.com/archive/1/archive/1/439432/100/100/threaded
http://security.gentoo.org/glsa/glsa-200607-13.xml
http://security.gentoo.org/glsa/glsa-200609-06.xml
BugTraq ID: 18859
http://www.securityfocus.com/bid/18859
http://www.frsirt.com/english/advisories/2006/2697
http://secunia.com/advisories/20972
http://secunia.com/advisories/21238
http://secunia.com/advisories/21295
http://secunia.com/advisories/21869
Common Vulnerability Exposure (CVE) ID: CVE-2006-3582
Fuente:www.securityspace.com
Search for in Google by Dino
sábado, 17 de febrero de 2007
Gentoo Security Advisory GLSA 200607-13 (audacious)
Publicado por http://hackinganddefense.blogspot.com/ Etiquetas: SEGURIDAD INFORMATICA en 10:22 p.m.
Suscribirse a:
Comentarios de la entrada (Atom)
No hay comentarios.:
Publicar un comentario