CVE-2006-0051
kaffeine - buffer overflow
EPSS 3.5%
Description
Buffer overflow in playlistimport.cpp in Kaffeine Player 0.4.2 through 0.7.1 allows user-assisted attackers to execute arbitrary code via long HTTP request headers when Kaffeine is "fetching remote playlists", which triggers the overflow in the http_peek function.
How to fix CVE-2006-0051
To remediate CVE-2006-0051, upgrade the affected package to a fixed version below.
- Debian/kaffeine—upgrade to 0.8-1 or later
- Debian/kaffeine—upgrade to 0.6-1sarge1 or later
Is CVE-2006-0051 being exploited?
Low — EPSS is 3.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.8-1
- from 0, < 0.6-1sarge1