CVE-2006-3668

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
18/07/2006
Last modified:
03/04/2025

Description

Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 20060716, including libdumb, allows user-assisted attackers to execute arbitrary code via a ".it" (Impulse Tracker) file with an envelope with a large number of nodes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dynamic_universal_music_bibliotheque:dumb:*:*:*:*:*:*:*:* 0.9.3 (including)