CVE-2006-4192
Summary
| CVE | CVE-2006-4192 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-17 01:04:00 UTC |
| Updated | 2018-10-17 21:33:00 UTC |
| Description | Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier, as used in GStreamer and possibly other products, allow user-assisted remote attackers to execute arbitrary code via (1) long strings in ITP files used by the CSoundFile::ReadITProject function in soundlib/Load_it.cpp and (2) crafted modules used by the CSoundFile::ReadSample function in soundlib/Sndfile.cpp, as demonstrated by crafted AMF files. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| libmodplug Buffer Overflow Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| ModPlug: Multiple buffer overflows — Gentoo Linux Documentation | GENTOO | security.gentoo.org | |
| SUSE Update for Multiple Packages - Advisories - Secunia | SECUNIA | secunia.com | |
| Ubuntu update for libmodplug - Advisories - Secunia | SECUNIA | secunia.com | |
| Security Announcement | SUSE | www.novell.com | |
| Secunia - Advisories - OpenMPT Buffer Overflow Vulnerabilities | SECUNIA | secunia.com | Vendor Advisory |
| 497154 – (CVE-2006-4192) CVE-2006-4192 libmodplug: Integer overflow when reading samples of AMF files | CONFIRM | bugzilla.redhat.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Gentoo update for libmodplug - Advisories - Secunia | SECUNIA | secunia.com | |
| gstreamer/gst-plugins-bad - 'Bad' GStreamer plugins and helper libraries (mirrored from https://gitlab.freedesktop.org/gstreamer/gst-plugins-bad) | CONFIRM | cgit.freedesktop.org | |
| SecurityReason - Stack and heap overflows in MODPlug Tracker/OpenMPT 1.17.02.43 and libmodplug 0.8 | SREASON | securityreason.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| OpenMPT Multiple Remote Code Execution Vulnerabilities | BID | www.securityfocus.com | |
| USN-521-1: libmodplug vulnerability | Ubuntu | UBUNTU | www.ubuntu.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| access.redhat.com | REDHAT | rhn.redhat.com | |
| aluigi.altervista.org/adv/mptho-adv.txt | MISC | aluigi.altervista.org | |
| Mandriva update for libmodplug - Advisories - Secunia | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.