CVE-2006-3668

Publication date 18 July 2006

Last updated 24 July 2024


Ubuntu priority

Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 20060716, including libdumb, allows user-assisted attackers to execute arbitrary code via a ”.it” (Impulse Tracker) file with an envelope with a large number of nodes.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
libdumb 9.10 karmic
Fixed 0.9.3-5
9.04 jaunty
Fixed 0.9.3-5
8.10 intrepid
Fixed 0.9.3-5
8.04 LTS hardy
Fixed 0.9.3-5
7.10 gutsy
Fixed 0.9.3-5
7.04 feisty
Fixed 0.9.3-5
6.10 edgy
Fixed 0.9.3-5
6.06 LTS dapper Ignored end of life