{"id":"DEBIAN-CVE-2006-4089","details":"Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of service (application crash), or have other unknown impact, via (1) a long Location field sent by a web server, which triggers an overflow in the reconnect function in reader/http/http.c; (2) a long URL sent by a web server when AlsaPlayer is seeking a media file for the playlist, which triggers overflows in new_list_item and CbUpdated in interface/gtk/PlaylistWindow.cpp; and (3) a long response sent by a CDDB server, which triggers an overflow in cddb_lookup in input/ccda/cdda_engine.c.","modified":"2026-09-12T06:47:30.750582775Z","published":"2006-08-11T10:04:00Z","upstream":["CVE-2006-4089"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2006-4089"}],"affected":[{"package":{"name":"alsaplayer","ecosystem":"Debian:12","purl":"pkg:deb/debian/alsaplayer?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.99.76-9"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-4089.json"}},{"package":{"name":"alsaplayer","ecosystem":"Debian:13","purl":"pkg:deb/debian/alsaplayer?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.99.76-9"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-4089.json"}},{"package":{"name":"alsaplayer","ecosystem":"Debian:14","purl":"pkg:deb/debian/alsaplayer?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.99.76-9"}]}],"ecosystem_specific":{"urgency":"medium"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2006-4089.json"}}],"schema_version":"1.9.0"}