Executive Summary
Summary | |
---|---|
Title | XMMS vulnerabilities |
Informations | |||
---|---|---|---|
Name | USN-445-1 | First vendor Publication | 2007-03-27 |
Vendor | Ubuntu | Last vendor Modification | 2007-03-27 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: Ubuntu 6.06 LTS: Ubuntu 6.10: After a standard system upgrade you need to restart XMMS or reboot your computer to effect the necessary changes. Details follow: Sven Krewitt of Secunia Research discovered that XMMS did not correctly handle BMP images when loading GUI skins. If a user were tricked into loading a specially crafted skin, a remote attacker could execute arbitrary code with user privileges. |
Original Source
Url : http://www.ubuntu.com/usn/USN-445-1 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:20310 | |||
Oval ID: | oval:org.mitre.oval:def:20310 | ||
Title: | DSA-1277-1 xmms - several | ||
Description: | Multiple errors have been found in the skin handling routines in xmms, the X Multimedia System. These vulnerabilities could allow an attacker to run arbitrary code as the user running xmms by inducing the victim to load specially crafted interface skin files. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1277-1 CVE-2007-0654 CVE-2007-0653 | Version: | 5 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | xmms |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2011-07-27 | Name : Fedora Update for xmms FEDORA-2011-9413 File : nvt/gb_fedora_2011_9413_xmms_fc15.nasl |
2011-07-27 | Name : Fedora Update for xmms FEDORA-2011-9421 File : nvt/gb_fedora_2011_9421_xmms_fc14.nasl |
2009-10-10 | Name : SLES9: Security update for XMMS File : nvt/sles9p5015928.nasl |
2009-03-23 | Name : Ubuntu Update for xmms vulnerabilities USN-445-1 File : nvt/gb_ubuntu_USN_445_1.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1277-1 (xmms) File : nvt/deb_1277_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
34406 | X MultiMedia System (xmms) Skin Bitmap Image Crafted Header Overflow |
34405 | X MultiMedia System (xmms) Skin Bitmap Image Crafted Header Memory Corruption |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-03-07 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_20e23b65a52e11e3ae3a00224d7c32a2.nasl - Type : ACT_GATHER_INFO |
2011-07-26 | Name : The remote Fedora host is missing a security update. File : fedora_2011-9413.nasl - Type : ACT_GATHER_INFO |
2011-07-26 | Name : The remote Fedora host is missing a security update. File : fedora_2011-9421.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 9 host is missing a security-related patch. File : suse9_11483.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_xmms-3075.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-445-1.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_xmms-3073.nasl - Type : ACT_GATHER_INFO |
2007-04-10 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1277.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 12:04:17 |
|