← Vulnerability feed

Vulnerability record · CVE-2006-4197 · published 17 August 2006

CVE-2006-4197: Libmusicbrainz vulnerability

Musicbrainz · Libmusicbrainz

Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the MBHttp::Download function in lib/http.cpp; and (2) a long URL in RDF data, as demonstrated by a URL in an rdf:resource field in an RDF XML document, which triggers overflows in many functions in lib/rdfparse.c.

7.5 CVSS 2.0 High EPSS 15% · top 3.4%
7.5CVSS 2.0 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
42References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the MBHttp::Download function in lib/http.cpp; and (2) a long URL in RDF data, as demonstrated by a URL in an rdf:resource field in an RDF XML document, which triggers overflows in many functions in lib/rdfparse.c.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://aluigi.altervista.org/adv/brainzbof-adv.txt
http://secunia.com/advisories/21404 ExploitVendor Advisory
http://secunia.com/advisories/21668
http://secunia.com/advisories/21699
http://secunia.com/advisories/22191
http://secunia.com/advisories/22393
http://secunia.com/advisories/22517
http://secunia.com/advisories/22639
http://security.gentoo.org/glsa/glsa-200610-09.xml
http://securityreason.com/securityalert/1399
http://securitytracker.com/id?1016691 Exploit
http://www.debian.org/security/2006/dsa-1162
http://www.mandriva.com/security/advisories?name=MDKSA-2006:157
http://www.novell.com/linux/security/advisories/2006_25_sr.html
http://www.securityfocus.com/archive/1/443205/100/0/threaded
http://www.securityfocus.com/archive/1/444843/100/0/threaded
http://www.securityfocus.com/bid/19508 Exploit
http://www.ubuntu.com/usn/usn-363-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/28367
https://exchange.xforce.ibmcloud.com/vulnerabilities/28368
https://issues.rpath.com/browse/RPL-610
http://aluigi.altervista.org/adv/brainzbof-adv.txt
http://secunia.com/advisories/21404 ExploitVendor Advisory
http://secunia.com/advisories/21668
http://secunia.com/advisories/21699
http://secunia.com/advisories/22191
http://secunia.com/advisories/22393
http://secunia.com/advisories/22517
http://secunia.com/advisories/22639
http://security.gentoo.org/glsa/glsa-200610-09.xml
http://securityreason.com/securityalert/1399
http://securitytracker.com/id?1016691 Exploit
http://www.debian.org/security/2006/dsa-1162
http://www.mandriva.com/security/advisories?name=MDKSA-2006:157
http://www.novell.com/linux/security/advisories/2006_25_sr.html
http://www.securityfocus.com/archive/1/443205/100/0/threaded
http://www.securityfocus.com/archive/1/444843/100/0/threaded
http://www.securityfocus.com/bid/19508 Exploit
http://www.ubuntu.com/usn/usn-363-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/28367

Track CVE-2006-4197 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2006-4197), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.