CVE-2007-1804
PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export assertion failure in do_read; (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0 sent on TCP port 9875, which triggers a length assertion failure in pa_memblock_new; or (3) an empty packet on UDP port 9875, which triggers a t assertion failure in pa_sdp_parse; and allows remote authenticated users to cause a denial of service (daemon crash) via a crafted packet on TCP port 9875 that (4) triggers a maxlength assertion failure in pa_memblockq_new, (5) triggers a size assertion failure in pa_xmalloc, or (6) plays a certain sound file.
EPSS 23.98% · 96.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| pulseaudio | pulseaudio | 0.9.5 |
Timeline
- Apr 2, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- 25431 third-party-advisory
- MDVSA-2008:065 vendor-advisory
- ADV-2007-1214 vdb
- http://aluigi.altervista.org/adv/pulsex-adv.txt url
- pulseaudio-assert-dos(33315) vdb
- SUSE-SR:2007:013 vendor-advisory
- 23240 vdb
- USN-465-1 vendor-advisory
- http://aluigi.org/poc/pulsex.zip url
- 25787 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-1804 advisory