Title : Ubuntu Security Update Fixes Libmusicbrainz Multiple Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2006-4022 CVE ID : CVE-2006-4197
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-12
Technical Description
Ubuntu has released updated packages to address multiple vulnerabilities identified in libmusicbrainz. These flaws are due to buffer overflow errors in the "lib/http.cpp" and "rdfparse.c" scripts when processing malformed HTTP redirections or URLs, which could be exploited by malicious servers to compromise a vulnerable system.