PT-2006-1013 · Dumb+1 · Dumb+1
Luigi Auriemma
·
Published
2006-07-17
·
Updated
2024-06-15
·
CVE-2006-3668
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
DUMB versions 0.9.3 and earlier
libdumb (affected versions not specified)
Description:
The issue is related to a heap-based buffer overflow in the
it read envelope function, which can be exploited by user-assisted attackers via a ".it" (Impulse Tracker) file with an envelope containing a large number of nodes, potentially allowing the execution of arbitrary code. Additionally, multiple vulnerabilities in the libdumb package may lead to disruptions in confidentiality, integrity, and availability of protected information, with possible remote exploitation.Recommendations:
For DUMB versions 0.9.3 and earlier: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
For libdumb: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dumb
Libdumb