CVE detail
CVE-2008-4829 — CVE-2008-4829
Published 2008-11-25 · Modified 2026-06-16 · Vendor streamripper · Product streamripper · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0648
EPSS probability
exploitation probability, 30d
93.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Multiple buffer overflows in lib/http.c in Streamripper 1.63.5 allow remote attackers to execute arbitrary code via (1) a long "Zwitterion v" HTTP header, related to the http_parse_sc_header function; (2) a crafted pls playlist with a long entry, related to the http_get_pls function; or (3) a crafted m3u playlist with a long File entry, related to the http_get_m3u function.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References