Lucene search

K
ubuntuUbuntuUSN-268-1
HistoryApr 07, 2006 - 12:00 a.m.

Kaffeine vulnerability

2006-04-0700:00:00
ubuntu.com
21

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.029

Percentile

90.9%

Releases

  • Ubuntu 5.10
  • Ubuntu 5.04

Details

Marcus Meissner discovered a buffer overflow in the http_peek()
function. By tricking an user into opening a specially crafted
playlist URL with Kaffeine, a remote attacker could exploit this to
execute arbitrary code with the user’s privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu5.10noarchkaffeine< *UNKNOWN
Ubuntu5.04noarchkaffeine< *UNKNOWN

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.029

Percentile

90.9%