Vulnerabilities > CVE-2006-4197 - Buffer Overflow vulnerability in Libmusicbrainz

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
musicbrainz
nessus
exploit available

Summary

Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the MBHttp::Download function in lib/http.cpp; and (2) a long URL in RDF data, as demonstrated by a URL in an rdf:resource field in an RDF XML document, which triggers overflows in many functions in lib/rdfparse.c.

Vulnerable Configurations

Part Description Count
Application
Musicbrainz
2

Exploit-Db

descriptionLibmusicbrainz 2.0.2/2.1.x Multiple Buffer Overflow Vulnerabilities. CVE-2006-4197. Dos exploit for linux platform
idEDB-ID:28384
last seen2016-02-03
modified2006-08-14
published2006-08-14
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/28384/
titleLibmusicbrainz 2.0.2/2.1.x - Multiple Buffer Overflow Vulnerabilities

Nessus

  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200610-09.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200610-09 (libmusicbrainz: Multiple buffer overflows) Luigi Auriemma reported a possible buffer overflow in the MBHttp::Download function of lib/http.cpp as well as several possible buffer overflows in lib/rdfparse.c. Impact : A remote attacker could be able to execute arbitrary code or cause Denial of Service by making use of an overly long
    last seen2020-06-01
    modified2020-06-02
    plugin id22920
    published2006-10-25
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/22920
    titleGLSA-200610-09 : libmusicbrainz: Multiple buffer overflows
  • NASL familyUbuntu Local Security Checks
    NASL idUBUNTU_USN-363-1.NASL
    descriptionLuigi Auriemma discovered multiple buffer overflows in libmusicbrainz. When a user made queries to MusicBrainz servers, it was possible for malicious servers, or man-in-the-middle systems posing as servers, to send a crafted reply to the client request and remotely gain access to the user
    last seen2020-06-01
    modified2020-06-02
    plugin id27943
    published2007-11-10
    reporterUbuntu Security Notice (C) 2007-2019 Canonical, Inc. / NASL script (C) 2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/27943
    titleUbuntu 5.04 / 5.10 / 6.06 LTS : libmusicbrainz-2.0, libmusicbrainz-2.1 vulnerability (USN-363-1)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-1162.NASL
    descriptionLuigi Auriemma discovered several buffer overflows in libmusicbrainz, a CD index library, that allow remote attackers to cause a denial of service or execute arbitrary code.
    last seen2020-06-01
    modified2020-06-02
    plugin id22704
    published2006-10-14
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/22704
    titleDebian DSA-1162-1 : libmusicbrainz-2.0 - buffer overflows
  • NASL familySuSE Local Security Checks
    NASL idSUSE_LIBMUSICBRAINZ-2042.NASL
    descriptionThis update fixes various buffer overflows that can by exploited by malicious servers to execute arbitrary code. (CVE-2006-4197)
    last seen2020-06-01
    modified2020-06-02
    plugin id29505
    published2007-12-13
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/29505
    titleSuSE 10 Security Update : libmusicbrainz (ZYPP Patch Number 2042)
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2006-157.NASL
    descriptionMultiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the MBHttp::Download function in lib/http.cpp; and (2) a long URL in RDF data, as demonstrated by a URL in an rdf:resource field in an RDF XML document, which triggers overflows in many functions in lib/rdfparse.c. The updated packages have been patched to correct this issue. Update : Packages are now available for Mandriva Linux 2007.
    last seen2020-06-01
    modified2020-06-02
    plugin id23901
    published2006-12-16
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/23901
    titleMandrake Linux Security Advisory : musicbrainz (MDKSA-2006:157-1)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_ED124F8C82A211DBB46B0012F06707F0.NASL
    descriptionSecurityFocus reports about libmusicbrainz : The libmusicbrainz library is prone to multiple buffer-overflow vulnerabilities because the application fails to check the size of the data before copying it into a finite-sized internal memory buffer. An attacker can exploit these issues to execute arbitrary code within the context of the application or to cause a denial-of-service condition.
    last seen2020-06-01
    modified2020-06-02
    plugin id23761
    published2006-12-04
    reporterThis script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/23761
    titleFreeBSD : libmusicbrainz -- multiple buffer overflow vulnerabilities (ed124f8c-82a2-11db-b46b-0012f06707f0)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_LIBMUSICBRAINZ-2044.NASL
    descriptionThis update fixes various buffer overflows that can by exploited by malicious servers to execute arbitrary code. (CVE-2006-4197)
    last seen2020-06-01
    modified2020-06-02
    plugin id27327
    published2007-10-17
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/27327
    titleopenSUSE 10 Security Update : libmusicbrainz (libmusicbrainz-2044)