CVE-2007-5825
Publication date 5 November 2007
Last updated 24 July 2024
Ubuntu priority
Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the “Authorization: Basic” HTTP header line.
Status
Package | Ubuntu Release | Status |
---|---|---|
mt-daapd | 8.10 intrepid |
Not affected
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy | Ignored end of life, was needed | |
7.04 feisty | Ignored end of life, was needed | |
6.06 LTS dapper | Not in release |