Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Gentoo: 200608-14 Normal: DUMB Heap Overflow Risk of Code Execution

gentoo
Calendar Grey August 8, 2006
Scroller Gentoo
The DUMB library has a critical heap overflow vulnerability that may enable execution of unauthorized code; ensure you upgrade to protect your systems from potential threats.
A heap-based buffer overflow in DUMB could result in the execution of arbitrary code.

Summary

Gentoo Linux Security Advisory GLSA 200608-14 https://security.gentoo.org/ Severity: Normal Title: DUMB: Heap buffer overflow Date: August 08, 2006 Bugs: #142387 ID: 200608-14

Synopsis ======= A heap-based buffer overflow in DUMB could result in the execution of arbitrary code.
Background ========= DUMB (Dynamic Universal Music Bibliotheque) is an IT, XM, S3M and MOD player library.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/dumb < 0.9.3-r1 >= 0.9.3-r1
========== Luigi Auriemma found a heap-based buffer overflow in the it_read_envelope function which reads the envelope values for volume, pan and pitch of the instruments referenced in a ".it" ...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround