PT-2006-1013 · Dumb+1 · Dumb+1

Luigi Auriemma

·

Publicado

2006-07-17

·

Atualizado

2024-06-15

·

CVE-2006-3668

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: DUMB versions 0.9.3 and earlier libdumb (affected versions not specified)
Description: The issue is related to a heap-based buffer overflow in the it read envelope function, which can be exploited by user-assisted attackers via a ".it" (Impulse Tracker) file with an envelope containing a large number of nodes, potentially allowing the execution of arbitrary code. Additionally, multiple vulnerabilities in the libdumb package may lead to disruptions in confidentiality, integrity, and availability of protected information, with possible remote exploitation.
Recommendations: For DUMB versions 0.9.3 and earlier: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For libdumb: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02977
CVE-2006-3668
DSA-1123
OPENSUSE-SU-2024:10729-1

Produtos afetados

Dumb
Libdumb