CVE Vulnerabilities

CVE-2008-1771

Published: Apr 16, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a large Content-Length.

Affected Software

NameVendorStart VersionEnd Version
FireflymediaserverFireflymediaserver0.2.4.1 (including)0.2.4.1 (including)
Mt-daapdUbuntufeisty*
Mt-daapdUbuntugutsy*
Mt-daapdUbuntuhardy*
Mt-daapdUbuntuupstream*

References