30945vdb entry
http://osvdb.org/show/osvdb/30945 CVE-2006-2465
MP3Info 0.8.5a - Buffer Overflow
Record summary
CVE-2006-2465 has a selected CVSS score of 5.1; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if mp3info is not installed setuid or setgid in any reasonable context, then this issue might not be a vulnerability.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBMP3Info 0.8.5a - Buffer OverflowExploitDB exploitby jsaccoNot analyzed1 file
ExploitDBMP3Info 0.8.5a - Local Buffer Overflow (SEH)ExploitDB exploitby Ayman SagyNot analyzed1 file
References
8packetstormsecurity.com
http://packetstormsecurity.com/files/124955/Mp3info-Stack-Buffer-Overflow.html packetstormsecurity.com
http://packetstormsecurity.com/files/125786/MP3Info-0.8.5-SEH-Buffer-Overflow.html 1016108vdb entry
http://securitytracker.com/id?1016108 32358exploit
http://www.exploit-db.com/exploits/32358 securiteam.com
http://www.securiteam.com/exploits/5GP0E15IKO.html 18016vdb entry
http://www.securityfocus.com/bid/18016 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-2465