PT-2018-9421 · Minisphere · Minisphere

Xiaoyinl

·

Publicado

2018-06-26

·

Atualizado

2018-08-28

·

CVE-2018-1000524

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions miniSphere versions prior to 5.2.10
Description The issue is related to an Integer Overflow in the layer resize() function in map engine.c, which can lead to a remote denial of service. This can be exploited by loading a specially-crafted map that calls SetLayerSize in its entry script.
Recommendations For miniSphere versions prior to 5.2.10, update to version 5.2.10 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the layer resize() function or restricting the loading of maps that call SetLayerSize in their entry scripts until a patch is applied.

Exploit

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000524

Produtos afetados

Minisphere