PT-2005-1444 · Armagetron · Armagetron+1

·

CVE-2005-0369

·

Publicado

2005-02-11

·

Atualizado

2025-01-16

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Armagetron versions 0.2.6.0 and earlier Armagetron Advanced versions 0.2.7.0 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This can be achieved by sending a packet with a large descriptor ID or claim id that exceeds the boundaries of an array.
Recommendations For Armagetron versions 0.2.6.0 and earlier, consider updating to a version later than 0.2.6.0 to resolve the issue. For Armagetron Advanced versions 0.2.7.0 and earlier, consider updating to a version later than 0.2.7.0 to resolve the issue. As a temporary workaround, consider restricting the size of descriptor ID and claim id in incoming packets to prevent the application crash.

Exploit

Correção

Improper Validation of Array Index

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-0369

Produtos afetados

Armagetron
Armagetron Advanced