PT-2006-2177 · Unknown · Tenes Empanadas Graciela

Luigi Auriemma

·

Published

2006-03-10

·

Updated

2017-07-20

·

CVE-2006-1150

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Tenes Empanadas Graciela (TEG) version 0.11.1
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by creating multiple users with long, identical nicknames, which triggers an off-by-one error due to the automatic appending of an underscore to the end of duplicate nicknames.
Recommendations For Tenes Empanadas Graciela (TEG) version 0.11.1, consider restricting the creation of users with identical nicknames to prevent the denial of service. As a temporary workaround, limit the length of nicknames to avoid triggering the off-by-one error. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1150

Affected Products

Tenes Empanadas Graciela