PT-2006-4869 · Festalon · Festalon

Luigi Auriemma

·

Published

2006-08-09

·

Updated

2011-03-08

·

CVE-2006-4024

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Festalon versions 0.5.0 through 0.5.5
Description The issue allows user-assisted attackers to cause a denial of service and possibly execute arbitrary code via a negative LoadAddr value in a HES file. This value is used as an offset in a memcpy operation, leading to a buffer underflow.
Recommendations For Festalon versions 0.5.0 through 0.5.5, consider restricting the use of the FESTAHES Load function in pce/hes.c until a patch is available to prevent potential denial of service and code execution attacks. As a temporary workaround, avoid using negative LoadAddr values in HES files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4024

Affected Products

Festalon