Vulnerabilities > CVE-2006-4046 - Buffer Overflow vulnerability in Open Cubic Player

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
open-cubic-player
exploit available

Summary

Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote attackers to execute arbitrary code via (1) a large .S3M file handled by the mpLoadS3M function, (2) a crafted .IT file handled by the itplayerclass::module::load function, (3) a crafted .ULT file handled by the mpLoadULT function, or (4) a crafted .AMS file handled by the mpLoadAMS function.

Vulnerable Configurations

Part Description Count
Application
Open_Cubic_Player
1

Exploit-Db

descriptionOpen Cubic Player <= 2.6.0pre6 / 0.1.10_rc5 Multiple BOF Exploit. CVE-2006-4046. Local exploit for windows platform
fileexploits/windows/local/2094.c
idEDB-ID:2094
last seen2016-01-31
modified2006-07-31
platformwindows
port
published2006-07-31
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/2094/
titleOpen Cubic Player <= 2.6.0pre6 / 0.1.10_rc5 - Multiple BoF Exploit
typelocal