PT-2007-6500 · Lfs Team · Live For Speed
Luigi Auriemma
·
Published
2007-10-15
·
Updated
2018-10-15
·
CVE-2007-5464
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Live for Speed versions 0.5X10 and earlier
Description:
The issue is a stack-based buffer overflow that can be triggered by a long skin name, allowing remote authenticated users to cause a denial of service, which results in a client crash, and potentially execute arbitrary code.
Recommendations:
For versions 0.5X10 and earlier, consider restricting the length of skin names to prevent the buffer overflow until a fix is available. As a temporary workaround, avoid using long skin names to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Live For Speed