Record summary

CVE-2007-5301 has a selected CVSS score of 6.8; EIP currently links 2 catalogued exploits.

Description

Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBAlsaPlayer 0.99.x - Vorbis Input Plugin OGG Processing Remote Buffer OverflowExploitDB exploitby ErikNot analyzed1 file
ExploitDB

PoC details
ExploitDBAlsaPlayer < 0.99.80-rc3 - Vorbis Input Local Buffer OverflowExploitDB exploitby Albert SellaresNot analyzed1 file
ExploitDB

PoC details

References

12