Libmikmod XCOM Handler Remote Heap Buffer Overflow Vulnerability
BID:19134
CVE-2006-3879 |Info
Libmikmod XCOM Handler Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 19134 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3879 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2006 12:00AM |
| Updated: | Mar 08 2007 03:35AM |
| Credit: | Luigi Auriemma is credited with the discovery of this vulnerability. |
| Vulnerable: |
libmikmod libmikmod 3.2.2 |
| Not Vulnerable: | |
Discussion
Libmikmod XCOM Handler Remote Heap Buffer Overflow Vulnerability
A buffer-overflow vulnerability occurs in the libmikmod library. This issue is due to the software's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow attackers to execute arbitrary machine code in the context of the affected application, which may facilitate the remote compromise of affected computers.
Versions 3.2.2 and prior are vulnerable; versions 2.x (which do not support the GT2 file format) are not vulnerable.
A buffer-overflow vulnerability occurs in the libmikmod library. This issue is due to the software's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue may allow attackers to execute arbitrary machine code in the context of the affected application, which may facilitate the remote compromise of affected computers.
Versions 3.2.2 and prior are vulnerable; versions 2.x (which do not support the GT2 file format) are not vulnerable.
Exploit / POC
Libmikmod XCOM Handler Remote Heap Buffer Overflow Vulnerability
Example exploit code has been provided:
Example exploit code has been provided:
Solution / Fix
Libmikmod XCOM Handler Remote Heap Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Libmikmod XCOM Handler Remote Heap Buffer Overflow Vulnerability
References:
References:
- libmikmod Web Site (libmikmod )
- Heap overflow in the GT2 loader of libmikmod 3.2.2 (Luigi Auriemma
)