Title : Multi-Threaded DAAP Daemon Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-1303 CVE ID : CVE-2008-1771
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-21
Technical Description
A vulnerability has been identified in mt-daapd (Multi-Threaded DAAP Daemon), which could be exploited by remote attackers to cause a denial of service or compromise an affected system. This issue is caused by a buffer overflow error in the "ws_getpostvars()" [src/webserver.c] function when processing a negative "Content-Length:" header value, which could be exploited by remote unauthenticated attackers to crash an affected application or execute arbitrary code.