Unrated severityNVD Advisory· Published Apr 16, 2008· Updated Apr 23, 2026
CVE-2008-1771
CVE-2008-1771
Description
Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a large Content-Length.
Affected products
1- cpe:2.3:a:fireflymediaserver:fireflymediaserver:0.2.4.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- bugs.debian.org/cgi-bin/bugreport.cginvd
- secunia.com/advisories/29917nvd
- secunia.com/advisories/29919nvd
- secunia.com/advisories/30661nvd
- sourceforge.net/project/shownotes.phpnvd
- www.debian.org/security/2008/dsa-1597nvd
- www.securityfocus.com/bid/28860nvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2008/1303/referencesnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/41850nvd
- www.redhat.com/archives/fedora-package-announce/2008-April/msg00446.htmlnvd
News mentions
0No linked articles in our index yet.