rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy in the RPLAYDATA case in rplayunpack in librplay/rplay.c, potentially reachable via packet data with no authentication.
{
"binaries": [
{
"binary_version": "3.3.2-15ubuntu1",
"binary_name": "devrplay3"
},
{
"binary_version": "3.3.2-15ubuntu1",
"binary_name": "librplay-perl"
},
{
"binary_version": "3.3.2-15ubuntu1",
"binary_name": "librplay3"
},
{
"binary_version": "3.3.2-15ubuntu1",
"binary_name": "rplay-client"
},
{
"binary_version": "3.3.2-15ubuntu1",
"binary_name": "rplay-contrib"
},
{
"binary_version": "3.3.2-15ubuntu1",
"binary_name": "rplay-server"
}
]
}{
"binaries": [
{
"binary_version": "3.3.2-16",
"binary_name": "devrplay3"
},
{
"binary_version": "3.3.2-16",
"binary_name": "librplay-perl"
},
{
"binary_version": "3.3.2-16",
"binary_name": "librplay3"
},
{
"binary_version": "3.3.2-16",
"binary_name": "rplay-client"
},
{
"binary_version": "3.3.2-16",
"binary_name": "rplay-contrib"
},
{
"binary_version": "3.3.2-16",
"binary_name": "rplay-server"
}
]
}{
"binaries": [
{
"binary_version": "3.3.2-17build1",
"binary_name": "devrplay3"
},
{
"binary_version": "3.3.2-17build1",
"binary_name": "librplay-perl"
},
{
"binary_version": "3.3.2-17build1",
"binary_name": "librplay3"
},
{
"binary_version": "3.3.2-17build1",
"binary_name": "rplay-client"
},
{
"binary_version": "3.3.2-17build1",
"binary_name": "rplay-contrib"
},
{
"binary_version": "3.3.2-17build1",
"binary_name": "rplay-server"
}
]
}{
"binaries": [
{
"binary_version": "3.3.2-18",
"binary_name": "devrplay3"
},
{
"binary_version": "3.3.2-18",
"binary_name": "librplay-perl"
},
{
"binary_version": "3.3.2-18",
"binary_name": "librplay3"
},
{
"binary_version": "3.3.2-18",
"binary_name": "rplay-client"
},
{
"binary_version": "3.3.2-18",
"binary_name": "rplay-contrib"
},
{
"binary_version": "3.3.2-18",
"binary_name": "rplay-server"
}
]
}{
"binaries": [
{
"binary_version": "3.3.2-18build2",
"binary_name": "devrplay3"
},
{
"binary_version": "3.3.2-18build2",
"binary_name": "librplay-perl"
},
{
"binary_version": "3.3.2-18build2",
"binary_name": "librplay3"
},
{
"binary_version": "3.3.2-18build2",
"binary_name": "rplay-client"
},
{
"binary_version": "3.3.2-18build2",
"binary_name": "rplay-contrib"
},
{
"binary_version": "3.3.2-18build2",
"binary_name": "rplay-server"
}
]
}{
"binaries": [
{
"binary_version": "3.3.2-21",
"binary_name": "devrplay3"
},
{
"binary_version": "3.3.2-21",
"binary_name": "librplay-perl"
},
{
"binary_version": "3.3.2-21",
"binary_name": "librplay3"
},
{
"binary_version": "3.3.2-21",
"binary_name": "rplay-client"
},
{
"binary_version": "3.3.2-21",
"binary_name": "rplay-contrib"
},
{
"binary_version": "3.3.2-21",
"binary_name": "rplay-server"
}
]
}{
"binaries": [
{
"binary_version": "3.3.2-22",
"binary_name": "devrplay3"
},
{
"binary_version": "3.3.2-22",
"binary_name": "librplay-perl"
},
{
"binary_version": "3.3.2-22",
"binary_name": "librplay3"
},
{
"binary_version": "3.3.2-22",
"binary_name": "rplay-client"
},
{
"binary_version": "3.3.2-22",
"binary_name": "rplay-contrib"
},
{
"binary_version": "3.3.2-22",
"binary_name": "rplay-server"
}
]
}