PT-2005-2620 · Zoid · Zoidcom

Luigi Auriemma

·

Published

2005-05-17

·

Updated

2017-07-11

·

CVE-2005-1643

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Zoidcom versions 1.0 beta 4 and earlier
Description The issue allows remote attackers to cause a denial of service via a crafted UDP packet with a large size value. This can lead to a memory allocation error or an out-of-bounds read.
Recommendations For Zoidcom versions 1.0 beta 4 and earlier, consider restricting access to the ZCom BitStream::Deserialize function until a patch is available. As a temporary workaround, implement packet size validation to prevent large size values from being processed.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1643

Affected Products

Zoidcom