LWN.net Logo

libdumb: arbitrary code execution

Package(s):libdumb CVE #(s):CVE-2006-3668
Created:July 24, 2006 Updated:August 9, 2006
Description: Luigi Auriemma discovered that DUMB, a tracker music library, performs insufficient sanitizing of values parsed from IT music files, which might lead to a buffer overflow and execution of arbitrary code if manipulated files are read.
Alerts:
Gentoo 200608-14 2006-08-08
Fedora FEDORA-EXTRAS-2006-003 2006-08-02
Debian DSA-1123-1 2006-07-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds