Rapid7 Vulnerability & Exploit Database

CESA-2005:033: alsa-lib security update

Free InsightVM Trial No credit card necessary
Watch Demo See how it all works
Back to Search

CESA-2005:033: alsa-lib security update

Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
04/27/2005
Created
07/25/2018
Added
03/12/2010
Modified
07/04/2017

Description

An updated alsa-lib package that fixes a flaw that disabled stack execution protection is now available for CentOS Linux 4. This update has been rated as having important security impact by the CentOS Security Response Team.

The alsa-lib package provides a library of functions for communication with kernel sound drivers. A flaw in the alsa mixer code was discovered that caused stack execution protection to be disabled for the libasound.so library. The effect of this flaw is that stack execution protection, through NX or Exec-Shield, would be disabled for any application linked to libasound. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0087 to this issue Users are advised to upgrade to this updated package, which contains a patched version of the library which correctly enables stack execution protection.

Solution(s)

  • centos-upgrade-alsa-lib
  • centos-upgrade-alsa-lib-devel

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;