CVE-2008-4829
Multiple buffer overflows in lib/http.c in Streamripper 1.63.5 allow remote attackers to execute arbitrary code via (1) a long "Zwitterion v" HTTP header, related to the http_parse_sc_header function; (2) a crafted pls playlist with a long entry,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in lib/http.c in Streamripper 1.63.5 allow remote attackers to execute arbitrary code via (1) a long "Zwitterion v" HTTP header, related to the http_parse_sc_header function; (2) a crafted pls playlist with a long entry, related to the http_get_pls function; or (3) a crafted m3u playlist with a long File entry, related to the http_get_m3u function.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 6.48% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- streamripper/streamripper
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/32562Vendor Advisory
- http://secunia.com/advisories/33052
- http://secunia.com/advisories/33061
- http://secunia.com/secunia_research/2008-50/
- http://securityreason.com/securityalert/4647
- http://www.debian.org/security/2008/dsa-1683
- http://www.osvdb.org/49997
- http://www.securityfocus.com/archive/1/498486/100/0/threaded
- http://www.securityfocus.com/bid/32356
- http://www.vupen.com/english/advisories/2008/3207
- http://secunia.com/advisories/32562Vendor Advisory
- http://secunia.com/advisories/33052
- http://secunia.com/advisories/33061
- http://secunia.com/secunia_research/2008-50/
- http://securityreason.com/securityalert/4647
- http://www.debian.org/security/2008/dsa-1683
- http://www.osvdb.org/49997
- http://www.securityfocus.com/archive/1/498486/100/0/threaded
- http://www.securityfocus.com/bid/32356
- http://www.vupen.com/english/advisories/2008/3207
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.