6

CVE-2007-4425

Exploit
Multiple buffer overflows in Live for Speed (LFS) demo, S1, and S2 allow remote authenticated users to (1) cause a denial of service (server crash) and probably execute arbitrary code via an ID 3 packet with a long nickname field, and (2) cause a denial of service (server crash) via an ID 10 packet containing a long string corresponding to an unavailable track.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.74% 0.842
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://aluigi.altervista/adv/lfsbof-adv.txt
http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065265.html
Exploit
http://secunia.com/advisories/26569
http://securityreason.com/securityalert/3030
http://www.securityfocus.com/archive/1/476516/100/0/threaded
http://www.securityfocus.com/bid/25327
http://www.vupen.com/english/advisories/2007/2975
https://exchange.xforce.ibmcloud.com/vulnerabilities/36021