PT-2018-9421 · Minisphere · Minisphere

Xiaoyinl

·

Published

2018-06-26

·

Updated

2018-08-28

·

CVE-2018-1000524

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions miniSphere versions prior to 5.2.10
Description The issue is related to an Integer Overflow in the layer resize() function in map engine.c, which can lead to a remote denial of service. This can be exploited by loading a specially-crafted map that calls SetLayerSize in its entry script.
Recommendations For miniSphere versions prior to 5.2.10, update to version 5.2.10 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the layer resize() function or restricting the loading of maps that call SetLayerSize in their entry scripts until a patch is applied.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000524

Affected Products

Minisphere