PT-2006-4966 · Dconnect · Dconnect Daemon

Luigi Auriemma

·

Published

2006-08-14

·

Updated

2018-10-17

·

CVE-2006-4125

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DConnect Daemon versions 0.7.0 and earlier
Description The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code. This is achieved by providing a large nickname that is not properly handled by the listen thread udp function in the main.c file.
Recommendations For DConnect Daemon versions 0.7.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4125

Affected Products

Dconnect Daemon