PT-2006-6856 · Neoengine · Neoengine

Luigi Auriemma

·

Publicado

2006-12-02

·

Atualizado

2008-09-05

·

CVE-2006-6226

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NeoEngine versions 0.8.2 and earlier
Description The issue is related to multiple format string vulnerabilities that can be exploited by remote attackers to cause a denial of service and possibly execute arbitrary code. This is achieved through vulnerable functions such as Console::Render in neoengine/console.cpp and TextArea::Render in neowtk/textarea.cpp.
Recommendations For NeoEngine versions 0.8.2 and earlier, consider disabling the Console::Render and TextArea::Render functions as a temporary workaround until a patch is available. Restrict access to the vulnerable modules neoengine/console.cpp and neowtk/textarea.cpp to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6226

Produtos afetados

Neoengine