PT-2006-2177 · Unknown · Tenes Empanadas Graciela
Luigi Auriemma
·
Publicado
2006-03-10
·
Atualizado
2017-07-20
·
CVE-2006-1150
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Tenes Empanadas Graciela (TEG) version 0.11.1
Description
The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by creating multiple users with long, identical nicknames, which triggers an off-by-one error due to the automatic appending of an underscore to the end of duplicate nicknames.
Recommendations
For Tenes Empanadas Graciela (TEG) version 0.11.1, consider restricting the creation of users with identical nicknames to prevent the denial of service. As a temporary workaround, limit the length of nicknames to avoid triggering the off-by-one error. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tenes Empanadas Graciela