Vulnerability Description
Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier allow local users to cause a denial of service (daemon crash) or gain privileges via a long HOME environment variable. NOTE: some of these details are obtained from third party information.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gxine | Gxine | <= 0.5.9 |
References
- http://osvdb.org/38320
- http://osvdb.org/38321
- http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=476891
- http://www.vupen.com/english/advisories/2007/0259
- http://xinehq.de/index.php/news?show_category_id=1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31604
- http://osvdb.org/38320
- http://osvdb.org/38321
- http://sourceforge.net/project/shownotes.php?group_id=9655&release_id=476891
- http://www.vupen.com/english/advisories/2007/0259
- http://xinehq.de/index.php/news?show_category_id=1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31604
FAQ
What is CVE-2007-0406?
CVE-2007-0406 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier allow local users to cau...
How severe is CVE-2007-0406?
CVE-2007-0406 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0406?
Check the references section above for vendor advisories and patch information. Affected products include: Gxine Gxine.