PT-2007-2766 · Conquest · Conquest

Published

2007-03-10

·

Updated

2018-10-16

·

CVE-2007-1371

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Conquest versions 8.2a and earlier
Description The issue involves multiple buffer overflows that can be exploited in different ways. Locally, users can gain privileges by querying a metaserver that sends a long server entry, which is processed by the metaGetServerList function. Remote metaservers can also execute arbitrary code via a long server entry processed by the same function. Additionally, exceeding the configured number of metaservers can have an unknown impact. Remote attackers can corrupt memory by sending a SP CLIENTSTAT packet with certain values of unum or snum.
Recommendations For Conquest versions 8.2a and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1371

Affected Products

Conquest