PT-2018-9421 · Minisphere · Minisphere
Xiaoyinl
·
Published
2018-06-26
·
Updated
2018-08-28
·
CVE-2018-1000524
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
miniSphere versions prior to 5.2.10
Description
The issue is related to an Integer Overflow in the
layer resize() function in map engine.c, which can lead to a remote denial of service. This can be exploited by loading a specially-crafted map that calls SetLayerSize in its entry script.Recommendations
For miniSphere versions prior to 5.2.10, update to version 5.2.10 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the
layer resize() function or restricting the loading of maps that call SetLayerSize in their entry scripts until a patch is applied.Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minisphere