Vulnerability CVE-2006-3668


Published: 2006-07-18   Modified: 2012-02-12

Description:
Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 20060716, including libdumb, allows user-assisted attackers to execute arbitrary code via a ".it" (Impulse Tracker) file with an envelope with a large number of nodes.

See advisories in our WLB2 database:
Topic
Author
Date
High
DUMB <= 0.9.3 heap overflow in it_read_envelope
Luigi Auriemma
21.07.2006

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:H/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.6/10
10/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Dynamic universal music bibliotheque -> DUMB 

 References:
http://xforce.iss.net/xforce/xfdb/27789
http://www.vupen.com/english/advisories/2006/2835
http://www.securityfocus.com/bid/19025
http://www.gentoo.org/security/en/glsa/glsa-200608-14.xml
http://www.debian.org/security/2006/dsa-1123
http://securityreason.com/securityalert/1240
http://secunia.com/advisories/21416
http://secunia.com/advisories/21184
http://secunia.com/advisories/21092
http://aluigi.altervista.org/adv/dumbit-adv.txt

Copyright 2024, cxsecurity.com

 

Back to Top