PT-2006-2177 · Unknown · Tenes Empanadas Graciela

Luigi Auriemma

·

Publicado

2006-03-10

·

Atualizado

2017-07-20

·

CVE-2006-1150

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenes Empanadas Graciela (TEG) version 0.11.1
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by creating multiple users with long, identical nicknames, which triggers an off-by-one error due to the automatic appending of an underscore to the end of duplicate nicknames.
Recommendations For Tenes Empanadas Graciela (TEG) version 0.11.1, consider restricting the creation of users with identical nicknames to prevent the denial of service. As a temporary workaround, limit the length of nicknames to avoid triggering the off-by-one error. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1150

Produtos afetados

Tenes Empanadas Graciela