Buffer overflow in discdb.c for grip 3.1.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the cddb lookup to return more matches than expected.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade gnome-vfs2-develUpgrade gnome-vfs2 | Dec 1, 2016 | May 2, 2005 |
| Debian | — | Upgrade gripUpgrade libcdaudio | Jul 30, 2024 | May 2, 2005 |
| Freebsd | — | Upgrade libcdaudioUpgrade grip | Dec 10, 2025 | Mar 14, 2005 |
| Gentoo Linux | — | Upgrade media-libs/libcdaudio.Upgrade media-sound/grip.Upgrade gnome-base/gnome-vfs. | Oct 30, 2017 | May 2, 2005 |
| Suse | — | Upgrade gnome-vfs2-docUpgrade gnome-vfs2-64bitUpgrade gnome-vfs2Upgrade gnome-vfsUpgrade gnome-vfs2-32bit | Feb 17, 2015 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub