5

CVE-2006-2393

Exploit
The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text strings to be appended to the player->client buffer, which causes an invalid memory access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Empire ServerEmpire Server Version4.3.0
Empire ServerEmpire Server Version4.3.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.76% 0.885
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://aluigi.altervista.org/adv/empiredos-adv.txt
Patch
Exploit
http://empserver.cvs.sourceforge.net/empserver/empserver/src/lib/player/
Patch
http://secunia.com/advisories/20094
Vendor Advisory
http://securityreason.com/securityalert/896
http://www.securityfocus.com/archive/1/433940/100/0/threaded
http://www.vupen.com/english/advisories/2006/1798
https://exchange.xforce.ibmcloud.com/vulnerabilities/26525