CVE-2005-0087: Medium severity redhat Enterprise Linux vulnerability
Published Feb 15, 2005
·Updated
The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.
Affected Software
2 affected components
redhat Enterprise Linux=4.0
Alsa-project Alsa-lib=1.0.6
Event History
Feb 15, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0087?
CVE-2005-0087 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2005-0087?
To fix CVE-2005-0087, update the alsa-lib package to the latest version that has stack protection enabled.
3
Which systems are affected by CVE-2005-0087?
CVE-2005-0087 affects Red Hat Enterprise Linux 4.0 systems that use alsa-lib version 1.0.6.
4
What vulnerabilities can be exploited due to CVE-2005-0087?
CVE-2005-0087 can be exploited in conjunction with other vulnerabilities in the libasound.so library.
5
Is there a patch available for CVE-2005-0087?
Yes, Red Hat has provided security patches for CVE-2005-0087 in their errata documentation.