CVE-2007-5301
alsaplayer - stack based buffer overflow in vorbis plugin
EPSS 10.2%
Description
Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments.
How to fix CVE-2007-5301
To remediate CVE-2007-5301, upgrade the affected package to a fixed version below.
- Debian/alsaplayer—upgrade to 0.99.80~rc4-1 or later
- Debian/alsaplayer—upgrade to 0.99.76-9+etch1 or later
- Debian/alsaplayer—upgrade to 0.99.79-3+lenny1 or later
Is CVE-2007-5301 being exploited?
Moderate — EPSS is 10.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 0.99.80~rc4-1
- from 0, < 0.99.76-9+etch1
- from 0, < 0.99.79-3+lenny1