7.6

CVE-2006-3668

Exploit
Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 20060716, including libdumb, allows user-assisted attackers to execute arbitrary code via a ".it" (Impulse Tracker) file with an envelope with a large number of nodes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.94% 0.95
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://aluigi.altervista.org/adv/dumbit-adv.txt
Exploit
http://secunia.com/advisories/21092
Vendor Advisory
http://secunia.com/advisories/21184
http://secunia.com/advisories/21416
Vendor Advisory
http://securityreason.com/securityalert/1240
http://www.debian.org/security/2006/dsa-1123
http://www.gentoo.org/security/en/glsa/glsa-200608-14.xml
http://www.securityfocus.com/bid/19025
http://www.vupen.com/english/advisories/2006/2835
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27789