5

CVE-2007-4426

Live for Speed (LFS) S1 and S2 allows remote attackers to cause a denial of service (server crash) via (1) a certain 0x00 byte in a pre-login ID 3 packet, which triggers a NULL dereference; or (2) a pre-login ID 5 packet that lacks certain strings, which triggers an invalid pointer dereference.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.6% 0.833
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://aluigi.altervista/adv/lfsbof-adv.txt
http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065265.html
http://secunia.com/advisories/26569
http://securityreason.com/securityalert/3030
http://www.securityfocus.com/archive/1/476516/100/0/threaded
http://www.vupen.com/english/advisories/2007/2975
https://exchange.xforce.ibmcloud.com/vulnerabilities/36019
https://exchange.xforce.ibmcloud.com/vulnerabilities/36020