CVE Database
/

CVE-2006-4197

Back to search

CVE-2006-4197

Published: Aug 17, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the MBHttp::Download function in lib/http.cpp; and (2) a long URL in RDF data, as demonstrated by a URL in an rdf:resource field in an RDF XML document, which triggers overflows in many functions in lib/rdfparse.c.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-1162
vendor-advisory
x_refsource_DEBIAN
22393
third-party-advisory
x_refsource_SECUNIA
22191
third-party-advisory
x_refsource_SECUNIA
22639
third-party-advisory
x_refsource_SECUNIA
21404
third-party-advisory
x_refsource_SECUNIA
USN-363-1
vendor-advisory
x_refsource_UBUNTU
19508
vdb-entry
x_refsource_BID
GLSA-200610-09
vendor-advisory
x_refsource_GENTOO
22517
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2006:025
vendor-advisory
x_refsource_SUSE
21699
third-party-advisory
x_refsource_SECUNIA
20060830 rPSA-2006-0161-1 libmusicbrainz
mailing-list
x_refsource_BUGTRAQ
libmusicbrainz-rdfparse-bo(28368)
vdb-entry
x_refsource_XF
21668
third-party-advisory
x_refsource_SECUNIA
1016691
vdb-entry
x_refsource_SECTRACK
MDKSA-2006:157
vendor-advisory
x_refsource_MANDRIVA
1399
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now