Submitted by KeesCook on Fri, 2007-05-25 23:31.
usn
Referenced CVEs:
CVE-2007-1804
Description:
===========================================================
Ubuntu Security Notice USN-465-1 May 25, 2007
pulseaudio vulnerability
CVE-2007-1804
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 7.04:
pulseaudio 0.9.5-5ubuntu4.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Luigi Auriemma discovered multiple flaws in pulseaudio's network
processing code. If an unauthenticated attacker sent specially crafted
requests to the pulseaudio daemon, it would crash, resulting in a denial
of service.


