Junglewise Threat Intelligence

CVE-1999-1240: cddbd CD database server buffer overflow in logging component

CVE-1999-1240 · Severity: high · CVSS 7.5 · Published 1996-11-26

Executive brief

A vulnerability exists in the cddbd CD database server, a service used to look up music CD information over a network. An attacker can exploit this flaw to take control of the server and execute unauthorized commands. This could lead to a complete system compromise, data theft, or disruption of the database service.

Technical details

A stack-based buffer overflow exists in the cddbd CD database server. The vulnerability is triggered when the application processes an excessively long log message, failing to perform adequate bounds checking before copying data into a fixed-size buffer. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the service, leading to arbitrary code execution with the privileges of the cddbd process. This is a classic buffer overflow vulnerability reachable over the network without user interaction.

Affected products

  • cddbd cddbd

Timeline

  • 1996-11-26: disclosed: Initial NVD publication date

References