PT-2005-1444 · Armagetron · Armagetron+1

Luigi Auriemma

·

Published

2005-02-11

·

Updated

2025-01-16

·

CVE-2005-0369

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Armagetron versions 0.2.6.0 and earlier Armagetron Advanced versions 0.2.7.0 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This can be achieved by sending a packet with a large descriptor ID or claim id that exceeds the boundaries of an array.
Recommendations For Armagetron versions 0.2.6.0 and earlier, consider updating to a version later than 0.2.6.0 to resolve the issue. For Armagetron Advanced versions 0.2.7.0 and earlier, consider updating to a version later than 0.2.7.0 to resolve the issue. As a temporary workaround, consider restricting the size of descriptor ID and claim id in incoming packets to prevent the application crash.

Exploit

Fix

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

CVE-2005-0369

Affected Products

Armagetron
Armagetron Advanced