CVE Vulnerabilities

CVE-2006-4192

Published: Aug 17, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 LOW
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier, as used in GStreamer and possibly other products, allow user-assisted remote attackers to execute arbitrary code via (1) long strings in ITP files used by the CSoundFile::ReadITProject function in soundlib/Load_it.cpp and (2) crafted modules used by the CSoundFile::ReadSample function in soundlib/Sndfile.cpp, as demonstrated by crafted AMF files.

Affected Software

NameVendorStart VersionEnd Version
TrackerModplug*1.17.02.43 (including)
Red Hat Enterprise Linux 4RedHatgstreamer-plugins-0:0.8.5-1.EL.3*
Gst-plugins-bad0.10Ubuntudapper*
Gst-plugins-bad0.10Ubuntuedgy*
LibmodplugUbuntudapper*
LibmodplugUbuntuedgy*

References