CVE-2005-0706

NameCVE-2005-0706
DescriptionBuffer overflow in discdb.c for grip 3.1.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the cddb lookup to return more matches than expected.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs304799, 305163

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
grip (PTS)sid, trixie4.6.1-2fixed
libcdaudio (PTS)bookworm, bullseye0.99.12p2-15fixed
sid, trixie0.99.12p2-16fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gnome-vfssource(unstable)1.0.5-5.1low305163
gnome-vfs2sourcesarge(not affected)
gnome-vfs2source(unstable)2.10.1-3
gripsource(unstable)3.2.0-4low
libcdaudiosource(unstable)0.99.9-2.1low304799

Notes

[sarge] - gnome-vfs2 <not-affected> (does not install the module with the vulnerable code)

Search for package or bug name: Reporting problems