PT-2006-4851 · Unknown · Bomberclone
Luigi Auriemma
·
Published
2006-08-07
·
Updated
2017-07-20
·
CVE-2006-4006
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BomberClone versions 0.11.6 and earlier
Description
The issue is related to the
do gameinfo function, which does not reset the packet data size. This causes the send pkg function to use the incorrect data size when sending a reply, allowing remote attackers to read portions of server memory.Recommendations
For BomberClone versions 0.11.6 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bomberclone