PT-2007-5800 · Doomsday · Doomsday

Publicado

2007-08-31

·

Atualizado

2018-10-15

·

CVE-2007-4642

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Doomsday versions 1.9.0-beta5.1 and earlier
Description: The issue arises from multiple buffer overflows that allow remote attackers to execute arbitrary code or cause a denial of service. This occurs when a long chat message is not properly handled by functions such as D NetPlayerEvent in d net.c, Msg Write in net msg.c, or when many commands are not properly handled by the NetSv ReadCommands function in d netsv.c. Additionally, a denial of service can be caused by a chat message without a final '0' character.
Recommendations: For Doomsday versions 1.9.0-beta5.1 and earlier, consider disabling the chat functionality or restricting the length of chat messages to prevent exploitation until a patch is available. As a temporary workaround, avoid using the D NetPlayerEvent function, Msg Write function, or the NetSv ReadCommands function in d netsv.c to handle chat messages or commands. Restrict access to the PKT CHAT message handling to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4642

Produtos afetados

Doomsday