Vulnerabilities > CVE-2006-2465 - Buffer Overflow vulnerability in Mp3Info 0.8.4

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
mp3info
exploit available

Summary

Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if mp3info is not installed setuid or setgid in any reasonable context, then this issue might not be a vulnerability.

Vulnerable Configurations

Part Description Count
Application
Mp3Info
1

Exploit-Db

  • descriptionMP3Info 0.8.5a - Buffer Overflow. CVE-2006-2465. Dos exploit for linux platform
    idEDB-ID:31220
    last seen2016-02-03
    modified2014-01-27
    published2014-01-27
    reporterjsacco
    sourcehttps://www.exploit-db.com/download/31220/
    titleMP3Info 0.8.5a - Buffer Overflow
  • descriptionMP3Info 0.8.5a - SEH Buffer Overflow Exploit. CVE-2006-2465. Local exploit for windows platform
    fileexploits/windows/local/32358.pl
    idEDB-ID:32358
    last seen2016-02-03
    modified2014-03-19
    platformwindows
    port
    published2014-03-19
    reporterAyman Sagy
    sourcehttps://www.exploit-db.com/download/32358/
    titleMP3Info 0.8.5a - SEH Buffer Overflow Exploit
    typelocal

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/125786/mp3info085a-overflow.txt
idPACKETSTORM:125786
last seen2016-12-05
published2014-03-19
reporterAyman Sagy
sourcehttps://packetstormsecurity.com/files/125786/MP3Info-0.8.5-SEH-Buffer-Overflow.html
titleMP3Info 0.8.5 SEH Buffer Overflow