5

CVE-2004-2592

Exploit
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to send data stored at a negative array offset, which is not handled when processing Configstrings and Baselines.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Id SoftwareQuake Ii Server Version3.20
Id SoftwareQuake Ii Server Version3.21
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.72% 0.884
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://archives.neohapsis.com/archives/bugtraq/2004-10/0299.html
http://secunia.com/advisories/13013
Vendor Advisory
Exploit
http://secur1ty.net/advisories/001
Vendor Advisory
http://securitytracker.com/id?1011979
Exploit
http://web.archive.org/web/20041130092749/www.r1ch.net/stuff/r1q2/
http://www.osvdb.org/11181
http://www.securityfocus.com/bid/11551
https://exchange.xforce.ibmcloud.com/vulnerabilities/17890