CVE-2006-3668

Dynamic Universal Music Bibliotheque < 0.9.3 - Heap-Based Buffer Overflow via IT File Envelope Nodes

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-3668. PoCs published by Luigi Auriemma.

AI-analyzed exploit summary This exploit demonstrates a heap overflow vulnerability in Dumb <= 0.9.3 by crafting a malicious .IT file that triggers a buffer overflow in the it_read_envelope function. The PoC creates an oversized pitch_envelope structure to overflow the IT_INSTRUMENT structure.

Description

Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 20060716, including libdumb, allows user-assisted attackers to execute arbitrary code via a ".it" (Impulse Tracker) file with an envelope with a large number of nodes.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Luigi Auriemma · cdoswindows
https://www.exploit-db.com/exploits/2037

This exploit demonstrates a heap overflow vulnerability in Dumb <= 0.9.3 by crafting a malicious .IT file that triggers a buffer overflow in the it_read_envelope function. The PoC creates an oversized pitch_envelope structure to overflow the IT_INSTRUMENT structure.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Dumb <= 0.9.3 (CVS 16 Jul 2006)
No auth needed
Prerequisites: Ability to deliver a malicious .IT file to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-1123
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21092
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1240
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200608-14.xml
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21184
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19025
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21416
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2835
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27789

Scores

EPSS 0.0994
EPSS Percentile 95.0%

Details

CWE
CWE-119
Status published
Products (1)
dynamic_universal_music_bibliotheque/dumb < 0.9.3
Published Jul 18, 2006
Tracked Since Feb 18, 2026