« Volver al listado

CVE-2006-3879

Estado: ModificadaMedia (5)—

Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial of service via a GRAOUMF TRACKER (GT2) module file with a large (0xffffffff) comment length value in an XCOM chunk.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-3879",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-07-27T01:04:00.000",
  "references": [
    {
      "url": "http://aluigi.altervista.org/adv/lmmgt2ho-adv.txt",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.org/poc/lmmgt2ho.zip",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/21196",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/1288",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/441006/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/19134",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2967",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.altervista.org/adv/lmmgt2ho-adv.txt",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://aluigi.org/poc/lmmgt2ho.zip",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/21196",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/1288",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/441006/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/19134",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2967",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-189"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial of service via a GRAOUMF TRACKER (GT2) module file with a large (0xffffffff) comment length value in an XCOM chunk."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer en la función loadChunk    en loaders/load_gt2.c en libmikmod de Mikmod Sound System 3.2.2 pemite a atacantes remotos provocar una denegación de servicio mediante un fichero de módulo GRAOUMF TRACKER (GT2) con un valor grande (0xffffffff) de longitud de comentario en un pedazo XCOM."
    }
  ],
  "lastModified": "2026-06-16T22:28:00.363",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:miod_vallat:mikmod:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85890D01-923A-48A3-A0ED-61C68EBC3B59"
            },
            {
              "criteria": "cpe:2.3:a:miod_vallat:mikmod:3.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6726186-70B0-497A-93FA-CED6A6BFEF83"
            },
            {
              "criteria": "cpe:2.3:a:miod_vallat:mikmod:3.1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E045CD1-4342-4EC6-A9BC-81160F71F4FC"
            },
            {
              "criteria": "cpe:2.3:a:miod_vallat:mikmod:3.1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7E29D51-7EC4-49AB-9663-1DE0791E4A42"
            },
            {
              "criteria": "cpe:2.3:a:miod_vallat:mikmod:3.1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6E6DA86-55B8-475F-93DC-B191BD2C0ADD"
            },
            {
              "criteria": "cpe:2.3:a:miod_vallat:mikmod:3.1.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C46A1FE-DE05-4C29-AE38-52431D85DD65"
            },
            {
              "criteria": "cpe:2.3:a:miod_vallat:mikmod:3.1.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0DE1B84B-9D48-4AFA-B586-BAC4C54B5B6C"
            },
            {
              "criteria": "cpe:2.3:a:miod_vallat:mikmod:3.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A49F98BB-8909-404D-B8FC-5F9177958691"
            },
            {
              "criteria": "cpe:2.3:a:miod_vallat:mikmod:3.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C6D083B-7E2B-424D-A762-8461D265B2E3"
            },
            {
              "criteria": "cpe:2.3:a:miod_vallat:mikmod:3.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29B60348-03A0-42E8-ABA5-8A4F38334FEE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "This issue does not affect versions of Mikmod 3.2.0-beta2 or prior.  Versions of Mikmod distributed with Red Hat Enterprise Linux 2.1, 3, and 4 are based on version 3.1.11 and are therefore not vulnerable to this issue.",
      "lastModified": "2006-08-16T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}