Executive Summary
Summary | |
---|---|
Title | New XMMS packages fix arbitrary code execution |
Informations | |||
---|---|---|---|
Name | DSA-1277 | First vendor Publication | 2007-04-04 |
Vendor | Debian | Last vendor Modification | 2007-04-04 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple errors have been found in the skin handling routines in xmms, the X Multimedia System. These vulnerabilities could allow an attacker to run arbitrary code as the user running xmms by inducing the victim to load specially crafted interface skin files. For the stable distribution (sarge), these problems have been fixed in version 1.2.10+cvs20050209-2sarge1 For the upcoming stable distrubution (etch) and the unstable distribution (sid), these problems have been fixed in versions 1:1.2.10+20061101-1etch1 and 1:1.2.10+20070401-1, respectively. We recommend that you upgrade your xmms packages. |
Original Source
Url : http://www.debian.org/security/2007/dsa-1277 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:20310 | |||
Oval ID: | oval:org.mitre.oval:def:20310 | ||
Title: | DSA-1277-1 xmms - several | ||
Description: | Multiple errors have been found in the skin handling routines in xmms, the X Multimedia System. These vulnerabilities could allow an attacker to run arbitrary code as the user running xmms by inducing the victim to load specially crafted interface skin files. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1277-1 CVE-2007-0654 CVE-2007-0653 | Version: | 5 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | xmms |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2011-07-27 | Name : Fedora Update for xmms FEDORA-2011-9413 File : nvt/gb_fedora_2011_9413_xmms_fc15.nasl |
2011-07-27 | Name : Fedora Update for xmms FEDORA-2011-9421 File : nvt/gb_fedora_2011_9421_xmms_fc14.nasl |
2009-10-10 | Name : SLES9: Security update for XMMS File : nvt/sles9p5015928.nasl |
2009-03-23 | Name : Ubuntu Update for xmms vulnerabilities USN-445-1 File : nvt/gb_ubuntu_USN_445_1.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1277-1 (xmms) File : nvt/deb_1277_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
34406 | X MultiMedia System (xmms) Skin Bitmap Image Crafted Header Overflow |
34405 | X MultiMedia System (xmms) Skin Bitmap Image Crafted Header Memory Corruption |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-03-07 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_20e23b65a52e11e3ae3a00224d7c32a2.nasl - Type : ACT_GATHER_INFO |
2011-07-26 | Name : The remote Fedora host is missing a security update. File : fedora_2011-9413.nasl - Type : ACT_GATHER_INFO |
2011-07-26 | Name : The remote Fedora host is missing a security update. File : fedora_2011-9421.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 9 host is missing a security-related patch. File : suse9_11483.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_xmms-3075.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-445-1.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_xmms-3073.nasl - Type : ACT_GATHER_INFO |
2007-04-10 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1277.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:26:34 |
|