CVE-2008-4829: streamripper - fix buffer overflow in all releases

Bug #309370 reported by Marian Sigler
254
Affects Status Importance Assigned to Milestone
streamripper (Ubuntu)
Invalid
Undecided
Unassigned
Nominated for Dapper by Marian Sigler
Declined for Gutsy by Luca Falavigna
Nominated for Hardy by Marian Sigler
Nominated for Intrepid by Marian Sigler

Bug Description

Binary package hint: streamripper

The buffer overflow has only been fixed in jaunty (1.63), but as the bug also is in 1.61 (see debian: http://www.debian.org/security/2008/dsa-1683) I assume that it occurs also in all other releases.

CVE References

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu
better. Since the package referred to in this bug is in universe or multiverse,
it is community maintained. If you are able, I suggest posting a debdiff for
this issue. When a debdiff is available, members of the security team will
review it and publish the package. See the following link for more information:
https://wiki.ubuntu.com/SecurityUpdateProcedures

Changed in streamripper:
status: New → Confirmed
Revision history for this message
Marian Sigler (maix42) wrote :

I just tried, but the diff they have [1] doesn't match the source file in that version (I tried the one in hardy, 1.63-beta-1). I don't want to patch it manually since I don't know if in that version there are other places were a fix is needed (I don't "speak" C). I'd be happy if someone who is able to would try to fix it. Debian bug is http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506377 if it helps.

[1] http://streamripper.cvs.sourceforge.net/viewvc/streamripper/sripper_1x/lib/http.c?view=patch&r1=1.50&r2=1.51&pathrev=sripper-1_64_0

Revision history for this message
dino99 (9d9) wrote :

That's quite old; report with newer active version if needed

Changed in streamripper (Ubuntu):
status: Confirmed → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.