ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8767-1: Snapcast vulnerability

mediumAdvisoryimportance 12
AI summary · glm-5.3

Ubuntu patches Snapcast mishandling of crafted JSON-RPC requests enabling remote code execution and data exposure.

Ubuntu security notice USN-8767-1 addresses a vulnerability in Snapcast, a multiroom audio streaming server. The software incorrectly handled crafted JSON-RPC requests, which could allow a remote attacker to execute arbitrary code or obtain sensitive information. Users are advised to update the snapcast package.

  • Crafted JSON-RPC requests could trigger arbitrary code execution
  • Remote attackers could also obtain sensitive information
Full article

It was discovered that Snapcast incorrectly handled crafted JSON-RPC requests. A remote attacker could possibly use this issue to execute arbitrary code or obtain sensitive information.

This source does not provide full text. Read it at ubuntu.com.