CVE-2008-1771

Publication date 16 April 2008

Last updated 24 July 2024


Ubuntu priority

Description

Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a large Content-Length.

Status

Package Ubuntu Release Status
mt-daapd 8.10 intrepid
Not affected
8.04 LTS hardy
Fixed 0.9~r1696-1.1ubuntu0.1
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities