PT-2008-4973 · Skulltag · Skulltag

Luigi Auriemma

·

Published

2008-08-12

·

Updated

2023-12-28

·

CVE-2008-3597

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Skulltag versions prior to 0.97d2-RC6
Description The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and daemon crash. This can be achieved by sending a "command 29" packet when the player is not in the game.
Recommendations For versions prior to 0.97d2-RC6, update to version 0.97d2-RC6 or later to resolve the issue. As a temporary workaround, consider restricting access to the daemon to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2008-3597

Affected Products

Skulltag