PT-2005-4281 · Unknown · Glider Collect'N Kill
Luigi Auriemma
·
Published
2005-11-03
·
Updated
2016-10-18
·
CVE-2005-3485
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Glider Collect'n kill version 1.0.0.0
Description
The issue allows remote attackers to execute arbitrary code via a "gl playerEnter" command with a long
player name. This occurs due to a buffer overflow.Recommendations
For version 1.0.0.0, consider restricting the length of the
player name variable to prevent buffer overflow until a patch is available. As a temporary workaround, disabling the gl playerEnter command can help minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glider Collect'N Kill