PT-2006-2177 · Unknown · Tenes Empanadas Graciela
Luigi Auriemma
·
Published
2006-03-10
·
Updated
2017-07-20
·
CVE-2006-1150
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Tenes Empanadas Graciela (TEG) version 0.11.1
Description
The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by creating multiple users with long, identical nicknames, which triggers an off-by-one error due to the automatic appending of an underscore to the end of duplicate nicknames.
Recommendations
For Tenes Empanadas Graciela (TEG) version 0.11.1, consider restricting the creation of users with identical nicknames to prevent the denial of service. As a temporary workaround, limit the length of nicknames to avoid triggering the off-by-one error. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenes Empanadas Graciela