Vulnerabilities > CVE-2007-1804 - Remote Denial of Service vulnerability in Pulseaudio 0.9.5

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
pulseaudio
nessus
exploit available

Summary

PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export assertion failure in do_read; (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0 sent on TCP port 9875, which triggers a length assertion failure in pa_memblock_new; or (3) an empty packet on UDP port 9875, which triggers a t assertion failure in pa_sdp_parse; and allows remote authenticated users to cause a denial of service (daemon crash) via a crafted packet on TCP port 9875 that (4) triggers a maxlength assertion failure in pa_memblockq_new, (5) triggers a size assertion failure in pa_xmalloc, or (6) plays a certain sound file.

Vulnerable Configurations

Part Description Count
Application
Pulseaudio
1

Exploit-Db

descriptionPulseAudio 0.9.5 Assert() Remote Denial of Service Vulnerability. CVE-2007-1804. Dos exploit for linux platform
idEDB-ID:29809
last seen2016-02-03
modified2007-04-02
published2007-04-02
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/29809/
titlePulseAudio 0.9.5 Assert Remote Denial of Service Vulnerability

Nessus

  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-465-1.NASL
    descriptionLuigi Auriemma discovered multiple flaws in pulseaudio
    last seen2020-06-01
    modified2020-06-02
    plugin id28065
    published2007-11-10
    reporterUbuntu Security Notice (C) 2007-2019 Canonical, Inc. / NASL script (C) 2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/28065
    titleUbuntu 7.04 : pulseaudio vulnerability (USN-465-1)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_PULSEAUDIO-3637.NASL
    descriptionThis update of pulseaudio fixes a denial-of-service bug that can be triggered remotely. (CVE-2007-1804)
    last seen2020-06-01
    modified2020-06-02
    plugin id27405
    published2007-10-17
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/27405
    titleopenSUSE 10 Security Update : pulseaudio (pulseaudio-3637)
  • NASL familyMandriva Local Security Checks
    NASL idMANDRIVA_MDVSA-2008-065.NASL
    descriptionLuigi Auriemma found a few programming errors in Pulseaudio, that can be used to crash the Pulseaudio daemon, by authenticated and unauthenticated users. The updated packages fix these issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id37991
    published2009-04-23
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/37991
    titleMandriva Linux Security Advisory : pulseaudio (MDVSA-2008:065)