Unrated severityNVD Advisory· Published Nov 25, 2008· Updated Apr 23, 2026
CVE-2008-4829
CVE-2008-4829
Description
Multiple buffer overflows in lib/http.c in Streamripper 1.63.5 allow remote attackers to execute arbitrary code via (1) a long "Zwitterion v" HTTP header, related to the http_parse_sc_header function; (2) a crafted pls playlist with a long entry, related to the http_get_pls function; or (3) a crafted m3u playlist with a long File entry, related to the http_get_m3u function.
Affected products
1- cpe:2.3:a:streamripper:streamripper:1.63.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- secunia.com/advisories/32562nvdVendor Advisory
- secunia.com/advisories/33052nvd
- secunia.com/advisories/33061nvd
- secunia.com/secunia_research/2008-50/nvd
- securityreason.com/securityalert/4647nvd
- www.debian.org/security/2008/dsa-1683nvd
- www.osvdb.org/49997nvd
- www.securityfocus.com/archive/1/498486/100/0/threadednvd
- www.securityfocus.com/bid/32356nvd
- www.vupen.com/english/advisories/2008/3207nvd
News mentions
0No linked articles in our index yet.