CVE-2006-3879 describes an integer overflow vulnerability in the libmikmod library, specifically within the loadChunk function of Mikmod Sound System 3.2.2, affecting products like miod_vallat mikmod. This flaw allows remote attackers to trigger a denial of service by providing a crafted GRAOUMF TRACKER (GT2) module file containing an excessively large comment length in an XCOM chunk. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), it represents a medium severity issue, requiring no authentication and having low attack complexity, but only leading to a denial of service. While there is no evidence of active exploitation or Metasploit/Nuclei modules, a proof-of-concept for a local heap overflow related to the GT2 loader exists on ExploitDB, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.3CPE matchmatch criteria | cpe:2.3:a:miod_vallat:mikmod:3.0.3:*:*:*:*:*:*:* | ||
3.1.6CPE matchmatch criteria | cpe:2.3:a:miod_vallat:mikmod:3.1.6:*:*:*:*:*:*:* | ||
3.1.7CPE matchmatch criteria | cpe:2.3:a:miod_vallat:mikmod:3.1.7:*:*:*:*:*:*:* | ||
3.1.8CPE matchmatch criteria | cpe:2.3:a:miod_vallat:mikmod:3.1.8:*:*:*:*:*:*:* | ||
3.1.9CPE matchmatch criteria | cpe:2.3:a:miod_vallat:mikmod:3.1.9:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.