Bug#304799: libcdaudio: CAN-2005-0706: Bufferoverflow in CDDB lookup parsing

2005-04-22 Thread Bastian Kleineidam
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I prepared a NMU for this bug. If you don't object I will upload it tomorrow. Regards, Bastian - -- ,''`. Bastian Kleineidam : :' :GnuPG SchlÃssel `. `'gpg --keyserver wwwkeys.pgp.net --recv-keys 3

Bug#304799: libcdaudio: CAN-2005-0706: Bufferoverflow in CDDB lookup parsing

2005-04-15 Thread Moritz Muehlenhoff
Package: libcdaudio Severity: grave Tags: security patch Justification: user security hole CAN-2005-0706 describes a buffer overflow in grip CDDB response parsing that can potentially be exploited to execute arbitrary code. libcdaudio contains the vulnerable code as well. Attached you can find a