PT-2006-2211 · Enet · Enet Library

Luigi Auriemma

·

Published

2006-03-13

·

Updated

2018-10-18

·

CVE-2006-1195

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ENet library version Jul 2005 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by sending a packet fragment with a large total data size, which triggers an application abort when memory allocation fails.
Recommendations For ENet library version Jul 2005 and earlier, consider applying a patch or fix to the enet protocol handle send fragment function in protocol.c to prevent memory allocation failures due to large packet fragments. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1195

Affected Products

Enet Library