CVE-2004-1034

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/03/2005
Last modified:
03/04/2025

Description

Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kaffeine:kaffeine_player:0.4.2:*:*:*:*:*:*:*
cpe:2.3:a:kaffeine:kaffeine_player:0.4.3:*:*:*:*:*:*:*
cpe:2.3:a:kaffeine:kaffeine_player:0.4.3b:*:*:*:*:*:*:*
cpe:2.3:a:kaffeine:kaffeine_player:0.5_rc1:*:*:*:*:*:*:*
cpe:2.3:a:xine:gxine:0.3:*:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*