PT-2007-5631 · Nabi Studios · Toribash

Luigi Auriemma

·

Publicado

2007-08-21

·

Atualizado

2018-10-15

·

CVE-2007-4450

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Toribash versions 2.71 and earlier
Description The server does not properly handle long commands, allowing remote attackers to trigger a protocol violation where data is sent to other clients without a required LF character, as demonstrated by a SAY command. The security impact of this violation is not clear, although it probably makes exploitation easier.
Recommendations For Toribash versions 2.71 and earlier, consider restricting or disabling the SAY command until a proper fix is available to prevent potential exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4450

Produtos afetados

Toribash