CVE-2007-5301

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
09/10/2007
Last modified:
09/04/2025

Description

Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:alsaplayer:alsaplayer:*:*:*:*:*:*:*:* 0.99.80-rc2 (including)