Vulnerabilities > CVE-2006-3879 - Numeric Errors vulnerability in Miod Vallat Mikmod

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
miod-vallat
CWE-189
exploit available

Summary

Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial of service via a GRAOUMF TRACKER (GT2) module file with a large (0xffffffff) comment length value in an XCOM chunk.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionlibmikmod <= 3.2.2 (GT2 loader) Local Heap Overflow PoC. CVE-2006-3879. Dos exploits for multiple platform
idEDB-ID:2073
last seen2016-01-31
modified2006-07-25
published2006-07-25
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/2073/
titlelibmikmod <= 3.2.2 GT2 loader Local Heap Overflow PoC

Statements

contributorMark J Cox
lastmodified2006-08-16
organizationRed Hat
statementThis issue does not affect versions of Mikmod 3.2.0-beta2 or prior. Versions of Mikmod distributed with Red Hat Enterprise Linux 2.1, 3, and 4 are based on version 3.1.11 and are therefore not vulnerable to this issue.