PT-2006-4966 · Dconnect · Dconnect Daemon

Luigi Auriemma

·

Publicado

2006-08-14

·

Atualizado

2018-10-17

·

CVE-2006-4125

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DConnect Daemon versions 0.7.0 and earlier
Description The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code. This is achieved by providing a large nickname that is not properly handled by the listen thread udp function in the main.c file.
Recommendations For DConnect Daemon versions 0.7.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4125

Produtos afetados

Dconnect Daemon