PT-2006-6856 · Neoengine · Neoengine

Luigi Auriemma

·

Published

2006-12-02

·

Updated

2008-09-05

·

CVE-2006-6226

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NeoEngine versions 0.8.2 and earlier
Description The issue is related to multiple format string vulnerabilities that can be exploited by remote attackers to cause a denial of service and possibly execute arbitrary code. This is achieved through vulnerable functions such as Console::Render in neoengine/console.cpp and TextArea::Render in neowtk/textarea.cpp.
Recommendations For NeoEngine versions 0.8.2 and earlier, consider disabling the Console::Render and TextArea::Render functions as a temporary workaround until a patch is available. Restrict access to the vulnerable modules neoengine/console.cpp and neowtk/textarea.cpp to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6226

Affected Products

Neoengine