PT-2007-5631 · Nabi Studios · Toribash

Luigi Auriemma

·

Published

2007-08-21

·

Updated

2018-10-15

·

CVE-2007-4450

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Toribash versions 2.71 and earlier
Description The server does not properly handle long commands, allowing remote attackers to trigger a protocol violation where data is sent to other clients without a required LF character, as demonstrated by a SAY command. The security impact of this violation is not clear, although it probably makes exploitation easier.
Recommendations For Toribash versions 2.71 and earlier, consider restricting or disabling the SAY command until a proper fix is available to prevent potential exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4450

Affected Products

Toribash